Lukas Panni
Lukas Panni
### Description During review of our SPDX-Files generated using FOSSology, we noticed that a `CMU-Mach` license was referenced as `CMU` (without `-Mach`). We believe that this is incorrect. Currently the...
**Describe the bug** The OSV API does not respect the distro qualifier when querying with a purl, potentially leading to false positive vulnerability reports. Specifically, this leads to false positives...
**Describe the bug** The OSV certifier seems to fully rely on the output of the OSV API to determine if a component represented by a purl is affected by a...