Skip to content
Discussion options

You must be logged in to vote

NVD only provides mapping to cpe-strings. Your components probably only have a PURL. OSS Index is thus used to map from PURL to CVEs.
If you disable that (or only use NVD) you will only get vulnerabilities for components that are specified with a cpe identifier.

Replies: 1 comment

Comment options

You must be logged in to vote
0 replies
Answer selected by whiteninja76
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants