fleet/server/vulnerabilities
Victor Lyuboslavsky a70c41d5ce
Fixed false positive CVE for Nextcloud Desktop (#39360)
<!-- Add the related story/sub-task/bug number, like Resolves #123, or
remove if NA -->
**Related issue:** Resolves #38911

* Fixed false positive CVE for Nextcloud Desktop.
* Fixed rare CPE error when software name sanitizes to empty (e.g. only
special characters)

# Checklist for submitter

- [x] Changes file added for user-visible changes in `changes/`,
`orbit/changes/` or `ee/fleetd-chrome/changes`.

## Testing

- [x] Added/updated automated tests
- [x] QA'd all new/changed functionality manually


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Bug Fixes**
  * Fixed false positive vulnerability detection for Nextcloud Desktop
* Resolved error occurring when software names contain only special
characters and sanitize to empty

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-02-05 13:13:38 -06:00
..
customcve Fixed false positive for msrc companion apps (#38824) 2026-01-28 13:02:31 -06:00
goval_dictionary validate generate-cve.yml outputs (#26752) 2025-03-12 14:49:47 -05:00
io Updating golangci-lint to 1.61.0 (#22973) 2024-10-18 12:38:26 -05:00
macoffice Fix CI: extend grace periods for MSRC feeds and expand test coverage for file validation. (#37991) 2026-01-07 10:28:20 -06:00
msrc Dedupe MSRC downloads/deletes when enrolled hosts include multiple builds of the same version of Windows (#27060) 2025-03-12 13:22:56 -05:00
nvd Fixed false positive CVE for Nextcloud Desktop (#39360) 2026-02-05 13:13:38 -06:00
oval Add false-positive filtering for OVAL scanning (#33357) 2025-09-25 16:28:27 -04:00
testdata Add false-positive filtering for OVAL scanning (#33357) 2025-09-25 16:28:27 -04:00
utils Add gosimple linter (#23250) 2024-10-29 14:17:51 -05:00