Skip to content

Set version to "unknown" for packages without a version

Igor Frenkel requested to merge ifrenkel/415104-invalid-iid-in-dep-path into master

What does this MR do?

"Invalid" dependencies are removed from the security report's dependencies list, but not from the dependency graphs causing an invalid iid reference. This MR brings the skipped dependency back and sets its version to unknown in order to pass the security report schema validation.

What are the relevant issue numbers?

Gemnasium analyzer can generate dependency_path... (gitlab-org/gitlab#415104 - closed) • Igor Frenkel • 16.10 • At risk

Does this MR meet the acceptance criteria?

Edited by Igor Frenkel

Merge request reports