-
Notifications
You must be signed in to change notification settings - Fork 31
Description
We performed xeol scanning for opensearch packages where we had opensearch version=1.3.20, it suppose to flag it as EOL but it didn't flag it.
Expected: opensearch version=1.3.20 should be flagged as EOL
Steps to reprduce: Do a scanning for opensearch software with version 1.3.20
Environment:
Scanning performed on linux environment.
Xeol version used:
Application: xeol
Version: 0.10.8
BuildDate: 2025-03-05T16:02:30Z
GitCommit: ff04129
GitDescription: v0.10.8
Platform: linux/amd64
GoVersion: go1.22.6
Compiler: gc
Syft Version: v1.10.0
Supported DB Schema: 1
Performed xeol scanning with verbose, below is the response.
/[0014] DEBUG searching for eol matches for pkg=Pkg(type=java-archive, name=opensearch-cli, version=1.3.20, upstreams=0)
[0014] DEBUG searching for eol matches for pkg=Pkg(type=java-archive, name=opensearch-core, version=1.3.20, upstreams=0)
[0014] DEBUG s