Update OssIndexAnalysisTask.java #5197
Open
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Removed workaround for OssIndexAnalysis when component had "v" as version prefix
Description
I've noticed that calling the OSS Index API
https://ossindex.sonatype.org/api/v3/component-reportwithpkg:composer/symfony/validator@v3.3.18correctly returns the vulnerability CVE-2024-50343, while calling the API withpkg:composer/symfony/validator@3.3.18(note the absence ofv) I get back no vulnerability.In the
OssIndexAnalysisTaskclass I found that theminimizePurl()method removes thevjust before calling the API, apparently because previously there was a bug (as explained in the comment block above the function definition) that now seems solved.Addressed Issue
#1220
Additional Details
Checklist