diff --git a/pkg/osvscanner/osvscanner.go b/pkg/osvscanner/osvscanner.go index bc334e7d7d..38ed2f7714 100644 --- a/pkg/osvscanner/osvscanner.go +++ b/pkg/osvscanner/osvscanner.go @@ -247,6 +247,10 @@ func queryDetermineVersions(repoDir string) (*osv.DetermineVersionResponse, erro // results with our regular git commit scanning. return filepath.SkipDir } + if _, ok := vendoredLibNames[strings.ToLower(info.Name())]; ok { + // Ignore nested vendored libraries, as they can cause bad matches. + return filepath.SkipDir + } return nil }