internal/vuln: do not count withdrawn vuln as affecting a package Currently, withdrawn vulnerabilities are still prominently displayed as if they are regular vulnerabilities when viewing a package. This is likely causing a lot of undue noise for users. Therefore, stop showing withdrawn vulnerabilities, similar to govulncheck. Users who want to see withdrawn vulnerabilities can check it directly on pkg.go.dev/vuln. Fixes golang/go#80941 Change-Id: Idb981b629e4bb31eb3f32e02fbb8cd326a6a6964 Reviewed-on: https://go-review.googlesource.com/c/pkgsite/+/817440 kokoro-CI: kokoro <noreply+kokoro@google.com> Reviewed-by: Nicholas Husin <husin@google.com> LUCI-TryBot-Result: golang-scoped@luci-project-accounts.iam.gserviceaccount.com <golang-scoped@luci-project-accounts.iam.gserviceaccount.com> Reviewed-by: Ethan Lee <ethanalee@google.com>
This repository hosts the source code of the pkg.go.dev website, and pkgsite, a documentation server program.
Pkg.go.dev is a website for discovering and evaluating Go packages and modules.
You can check it out at https://pkg.go.dev.
pkgsite program extracts and generates documentation for Go projects.
Example usage:
$ go install golang.org/x/pkgsite/cmd/pkgsite@latest $ cd myproject $ pkgsite -open .
For more information, see the pkgsite documentation.
pkgsite provides a REST API for retrieving package and module information. The API endpoints include:
/v1/package/{path}: Information about the package at {path}./v1/module/{path}: Information about the module at {path}./v1/versions/{path}: Versions of the module at {path}./v1/packages/{path}: Information about packages of the module at {path}./v1/search: Search results./v1/symbols/{path}: List of symbols for the package at {path}./v1/imported-by/{path}: Paths of packages importing the package at {path}./v1/vulns/{path}: Vulnerabilities of the module at {path}.For detailed documentation of parameters and response schemas, see the documentation page served at /api, or refer directly to the annotated source code in internal/api/api.go.
If you want to report a bug or have a feature suggestion, please first check the known issues to see if your issue is already being discussed. If an issue does not already exist, feel free to file an issue.
For answers to frequently asked questions, see pkg.go.dev/about.
You can also chat with us on the #pkgsite Slack channel on the Gophers Slack.
We would love your help!
Our canonical Git repository is located at go.googlesource.com/pkgsite. There is a mirror of the repository at github.com/golang/pkgsite.
To contribute, please read our contributing guide.
Unless otherwise noted, the Go source files are distributed under the BSD-style license found in the LICENSE file.