Does disabling 'OSS Index analyzer' breake the analysis for components like golang.org/x/crypto #5523
-
|
Hi, re recently turned of teh OSS Index analyzer as its now needs a api token . which is just abit of extra config i havent sorted out yet. |
Beta Was this translation helpful? Give feedback.
Replies: 1 comment
-
|
NVD only provides mapping to cpe-strings. Your components probably only have a PURL. OSS Index is thus used to map from PURL to CVEs. |
Beta Was this translation helpful? Give feedback.
NVD only provides mapping to cpe-strings. Your components probably only have a PURL. OSS Index is thus used to map from PURL to CVEs.
If you disable that (or only use NVD) you will only get vulnerabilities for components that are specified with a cpe identifier.