False positive CVE-2017-18589 rust package matching cookie npm package #931
Labels
bug
Something isn't working
changelog-ignore
Don't include this issue in the release changelog
false-positive
What happened:
We have cookie in our dependencies. When scanning our repository we get a false positive on cookie Rust package
What you expected to happen:
I expect npm cookie package not to match CVEs against "cookie" Rust package.
How to reproduce it (as minimally and precisely as possible):
Anything else we need to know?:
Environment:
grype version
:cat /etc/os-release
or similar):The text was updated successfully, but these errors were encountered: