google / osv.dev

Open source vulnerability DB and triage service.

Home Page:https://osv.dev

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

Advisories deleted from source Git repository not being marked as withdrawn

andrewpollock opened this issue · comments

Describe the bug
Whilst doing some validation analysis for bitnami/vulndb#336 I noticed that records now showing as deleted are not marked as withdrawn in OSV.dev

Then I remembered #829 removed this behaviour due to some sort of blip at the time in the GitHub Advisory Database, whereas a safer approach would be to do a threshold-based operation like what's being done for GCS in #2030

Expected behaviour
I was of the expectation that deleted records were marked as withdrawn and that Git-based source imports would catch up to the commits deleting a record

Additional context