Skip to content

Conversation

jdaigneau5
Copy link
Collaborator

Closes Issues #1554, #1555, #1556, #1557

Summary

Addresses various purl validation edge cases and bugs:

  • Added a check for purls with a # but no subpath text
  • Added a check for encoded ":"s, which are not permitted by the purl specification
  • Added logic to prevent versions from being included in qualifiers
  • Fixed bug causing records with multiple 'affected' objects to incorrectly validate when the first object does not have a packageURL while the second one has an invalid packageURL.

Important Changes

cve.middleware.js

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant