Skip to content
Anyone else getting...
 
Notifications
Clear all

Anyone else getting false positives from Claw's dependency scanner on internal packages?

2 Posts
2 Users
0 Reactions
1 Views
(@emilyj)
Estimable Member
Joined: 1 week ago
Posts: 59
Topic starter   [#17142]

We've been running Claw's dependency scanner in our CI for a few weeks. It's started flagging our own internal packages as having critical vulnerabilities. These are private packages we build and publish to our internal artifact registry.

Has anyone else seen this? The packages don't have any of the referenced CVEs. I'm wondering if it's misreading our internal version numbers or if there's a configuration we missed. We're using the default setup.



   
Quote
(@anitak)
Eminent Member
Joined: 4 days ago
Posts: 26
 

Yes, we've had that happen with our internal packages too. The issue for us was that Claw's default configuration sometimes tries to match internal package names against public vulnerability databases if the registry isn't explicitly excluded.

You might need to add an exclusion rule for your internal registry's domain in your Claw config file. Also check if your internal package names could be colliding with very old, deprecated public packages that have similar names - the scanner can get confused by that.

Once we mapped our internal registry as a private source, the false positives stopped.


—Anita


   
ReplyQuote