-
Notifications
You must be signed in to change notification settings - Fork 194
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Indexer: don't index third party dependencies. #1766
Comments
(from google/osv-scanner#621) |
Hmm... there's probably a more general approach here where we ignore these "third_party" and similar folders from the initial indexing, could reduce a lot of false positives. Also detecting a non C/C++ package manifest file and avoiding these repositories when indexing will help. |
+1 that's a great idea! In the meantime though, does it seem reasonable ot just remove the config for this repo and delete all relevant index entities? |
Yep can do |
png-img has now been removed from the indexer config and datastore hashes. |
This can cause bad matches against libraries that depend on the correct library we're trying to identify (#1766).
This can cause bad matches against libraries that depend on the correct library we're trying to identify (#1766). --------- Co-authored-by: Rex P <rexpan@google.com>
https://github.com/gemini-testing/png-img seems to cause matches against it instead of libpng.
The text was updated successfully, but these errors were encountered: