Skip to content

Maven advisories missing scala SBT suffixes in package names #5781

Closed
@oliverchang

Description

@oliverchang

Originally filed in google/osv-scanner#1780.

Advisories in https://osv.dev/vulnerability/GHSA-p7c9-8xx8-h74f are missing package names with Scala SBT suffixes, e.g. https://central.sonatype.com/artifact/org.apache.kafka/kafka_2.13 and https://central.sonatype.com/artifact/org.apache.kafka/kafka_2.12 are technically different packages.

This leads to false negatives during scanning.

Ref: https://www.scala-sbt.org/1.x/docs/Cross-Build.html#Publishing+conventions

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions