Related to #10117.
The advisory GHSA-x37h-cx7x-wm76 is linked to a CVE and OSV advisory, but not to any github repository.
The OSV data contains the repository, see https://github.com/ocaml/security-advisories/blob/generated-osv/2026/OSEC-2026-15.json
{
"type": "GIT",
"repo": "https://github.com/mirage/mirage-crypto.git",
"events": [
{
"introduced": "0"
},
{
"fixed": "1f0bf67044e67cf6e46911fcd77a0ff706b6c3e7"
}
]
}
It would be nice if the advisory import system could recognize github URLs from CVE or OSV metadata, and link them to the appropriate repository.
This change would benefit any ecosystem that uses OSV, but is not yet a recognized ecosystem by Github, without having to add special supported for each ecosystem in turn: you'd only need to implement the generic handling to recognize the repository from OSV advisories once, and it'd work for all advisories on OSV.
Related to #10117.
The advisory GHSA-x37h-cx7x-wm76 is linked to a CVE and OSV advisory, but not to any github repository.
The OSV data contains the repository, see https://github.com/ocaml/security-advisories/blob/generated-osv/2026/OSEC-2026-15.json
{ "type": "GIT", "repo": "https://github.com/mirage/mirage-crypto.git", "events": [ { "introduced": "0" }, { "fixed": "1f0bf67044e67cf6e46911fcd77a0ff706b6c3e7" } ] }It would be nice if the advisory import system could recognize github URLs from CVE or OSV metadata, and link them to the appropriate repository.
This change would benefit any ecosystem that uses OSV, but is not yet a recognized ecosystem by Github, without having to add special supported for each ecosystem in turn: you'd only need to implement the generic handling to recognize the repository from OSV advisories once, and it'd work for all advisories on OSV.