internal/govulncheck: report only version for Summary.FixedIn/FoundIn

Initially I thought <pkgpath>@<version> may be helpful when the
suggested fix requires to use different package/module than the
currently used package. However, that can be a non-trivial change
most likely, and it's better to communicate differently instead.

Include only the version (either 'v' or 'go' prefixed).

This change does not affect the regular govulncheck text output format
but affects the version fields of Summary type.

Change-Id: I6712ad760349f05e7b092ea3c9c758863600b03e
Reviewed-on: https://go-review.googlesource.com/c/vuln/+/440217
TryBot-Result: Gopher Robot <gobot@golang.org>
Reviewed-by: Julie Qiu <julieqiu@google.com>
Run-TryBot: Hyang-Ah Hana Kim <hyangah@gmail.com>
3 files changed
tree: 6c2a93412a9293e29e148a1bc66685977445bb00
  1. client/
  2. cmd/
  3. devtools/
  4. doc/
  5. exp/
  6. internal/
  7. osv/
  8. vulncheck/
  9. .gitignore
  10. all_test.go
  11. checks.bash
  12. CONTRIBUTING.md
  13. go.mod
  14. go.sum
  15. LICENSE
  16. PATENTS
  17. README.md
  18. tools_test.go
README.md

Go Vulnerability Management

Go Reference

This repository contains packages for accessing and analyzing data from the Go Vulnerability Database. It contains the following:

  • Package client: a client for interacting with the Go vulnerability database
  • Package vulncheck: an API for detecting vulnerabilities in Go packages
  • Command govulncheck: a CLI for detecting vulnerabilities in Go packages

Check out https://go.dev/security/vuln for more information about the Go vulnerability management system.

Privacy Policy

The privacy policy for govulncheck can be found at https://vuln.go.dev/privacy.

License

Unless otherwise noted, the Go source files are distributed under the BSD-style license found in the LICENSE file.

Database entries available at https://vuln.go.dev are distributed under the terms of the CC-BY 4.0 license.