vulnfeeds: infer introduced and fixed versions from a GitHub compare URL
#2,924 opened on Nov 27, 2024
Repository metrics
- Stars
- (2,810 stars)
- PR merge metrics
- (PR metrics pending)
Description
Is your feature request related to a problem? Please describe.
There is an opportunity to infer the introduced and fixed versions from a CVE's reference when it contains a URL like https://github.com/JSONPath-Plus/JSONPath/compare/v9.0.0...v10.1.0
Describe the solution you'd like Today, https://github.com/google/osv.dev/blob/068dfb2ce8c8b92bf92fed40ab602c03084d56c4/vulnfeeds/cves/versions.go#L808-L814
prefers to use any commit references as a fixed commit over extracting versions and then attempting to map those to a commit.
Potentially before https://github.com/google/osv.dev/blob/068dfb2ce8c8b92bf92fed40ab602c03084d56c4/vulnfeeds/cves/versions.go#L902-L909 this could look for references like https://github.com/kovidgoyal/kitty/compare/v0.26.1...v0.26.2 and use this as an introduced..fixed version range.
Describe alternatives you've considered
I considered last_affected over fixed, but given we already make the other assumption about commit references being fixed, I figured we might as well double down on it here 😃
Additional context This would help the likes of CVE-2024-21534 convert in an un-analyzed state.