google/osv.dev

vulnfeeds: infer introduced and fixed versions from a GitHub compare URL

Open

#2,924 opened on Nov 27, 2024

View on GitHub
 (0 comments) (0 reactions) (0 assignees)Go (339 forks)auto 404
enhancementgood first issuevulnfeeds

Repository metrics

Stars
 (2,810 stars)
PR merge metrics
 (PR metrics pending)

Description

Is your feature request related to a problem? Please describe. There is an opportunity to infer the introduced and fixed versions from a CVE's reference when it contains a URL like https://github.com/JSONPath-Plus/JSONPath/compare/v9.0.0...v10.1.0

Describe the solution you'd like Today, https://github.com/google/osv.dev/blob/068dfb2ce8c8b92bf92fed40ab602c03084d56c4/vulnfeeds/cves/versions.go#L808-L814

prefers to use any commit references as a fixed commit over extracting versions and then attempting to map those to a commit.

Potentially before https://github.com/google/osv.dev/blob/068dfb2ce8c8b92bf92fed40ab602c03084d56c4/vulnfeeds/cves/versions.go#L902-L909 this could look for references like https://github.com/kovidgoyal/kitty/compare/v0.26.1...v0.26.2 and use this as an introduced..fixed version range.

Describe alternatives you've considered I considered last_affected over fixed, but given we already make the other assumption about commit references being fixed, I figured we might as well double down on it here 😃

Additional context This would help the likes of CVE-2024-21534 convert in an un-analyzed state.

Contributor guide