mirror of
https://github.com/fleetdm/fleet
synced 2026-05-09 10:11:03 +00:00
For #22723. Bundle IDs pulled from installs of the software, with regexes being starts-with matches to include EAPs in matches. Used the products list from CVE-2024-37051 to match up NVD product names (which is why Writerside isn't included here; it doesn't have any published vulns yet). This fixes vuln detection in e.g. GoLand EAPs when the app name is something other than the product name, similar to what we've done with IntelliJ and PyCharm (but omitting homebrew handling for now). No changes file as this doesn't need to be cherry-picked, and it will go out in the next NVD pull after merged to `main`. # Checklist for submitter - [x] Added/updated automated tests - [x] A detailed QA plan exists on the associated ticket (if it isn't there, work with the product group's QA engineer to add it) - [x] Manual QA for all new/changed functionality |
||
|---|---|---|
| .. | ||
| customcve | ||
| goval_dictionary | ||
| io | ||
| macoffice | ||
| msrc | ||
| nvd | ||
| oval | ||
| testdata | ||
| utils | ||