Package
ollama-fips
Component
github.com/ollama/ollama
Latest update
7.5
CVSS V3
Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.
Start for freeStatus
Justification
Impact
Not vulnerable. GHSA-9gcr-28rp-cc24 / CVE-2025-0317 affects github.com/ollama/ollama <= 0.3.14 only; upstream records no fixed version because later releases are not affected. This package ships ollama 0.17.1-0.30.10, above the affected range. The detection originates from the Go vulnerability database record (GO-2025-3559) omitting the last_affected 0.3.14 bound carried by the GHSA/OSV data, causing the scanner to over-match.
Status