Skip to content

Conversation

willmurphyscode
Copy link
Contributor

When processing CPEs in the NVD provider, if a CPE seems to be for a JVM based on its package namme, set its version type to be "jvm" so that grype knows at match time to use special comparison logic for JVM versions.

When processing CPEs in the NVD provider, if a CPE seems to be for a
JVM based on its package namme, set its version type to be "jvm" so that
grype knows at match time to use special comparison logic for JVM
versions.

Signed-off-by: Will Murphy <[email protected]>
@willmurphyscode willmurphyscode self-assigned this Aug 22, 2025
@willmurphyscode willmurphyscode moved this to In Review in OSS Aug 22, 2025
@willmurphyscode willmurphyscode enabled auto-merge (squash) August 22, 2025 15:27
@willmurphyscode willmurphyscode merged commit 60e433c into main Aug 22, 2025
11 checks passed
@willmurphyscode willmurphyscode deleted the fix-jvm-versions-v6 branch August 22, 2025 15:45
@github-project-automation github-project-automation bot moved this from In Review to Done in OSS Aug 22, 2025
@westonsteimel westonsteimel added the bug Something isn't working label Aug 22, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bug Something isn't working

Projects

Archived in project

Development

Successfully merging this pull request may close these issues.

2 participants