Skip to content

fix: scope package VEX suppression to package#2907

Open
huynhtrungcip wants to merge 1 commit into
google:mainfrom
huynhtrungcip:fix-package-vex-scope
Open

fix: scope package VEX suppression to package#2907
huynhtrungcip wants to merge 1 commit into
google:mainfrom
huynhtrungcip:fix-package-vex-scope

Conversation

@huynhtrungcip

Copy link
Copy Markdown

Summary

  • apply ComponentNotPresent package VEX signals to the annotated package instead of the entire source
  • remove source-wide rendered-output suppression for PackageSource ExperimentalPES
  • add a regression test for sibling packages sharing one source

Tests

  • go test ./pkg/osvscanner ./internal/output

@huynhtrungcip huynhtrungcip force-pushed the fix-package-vex-scope branch from a1da0b7 to a272fb9 Compare July 3, 2026 02:00
@huynhtrungcip huynhtrungcip force-pushed the fix-package-vex-scope branch from a272fb9 to 697f8d7 Compare July 3, 2026 02:04
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant