aboutcode-org / aboutcode-org/vulnerablecode

Use `affected` instead of `versionUnaffected` for reporting fixed versions from DEPS

Open
#1,153 0 comments 0 reactions 0 assignees View on GitHub
enhancement VulnTotal
Dominant language
Python
Stars
702
Forks
328
Avg merge
3d 8h
Merged PRs (30d)
3

Description

Currently, we're reporting `versionUnaffected` as the fixed version which is not precisely the fixed version.
We can make use of `affected` to get the fixed version.

```json
"affected": "{[0.0.0-0:2.1.3)}",
"rawAffected": "Introduced: 0, Fixed: 2.1.3",
```
![Screenshot 2023-03-17 at 1 39 00 PM](https://user-images.githubusercontent.com/44315208/225856783-58d4a131-f40a-4eee-9a3c-027b476e1d69.png)




> **Warning**
> Don't use `rawAffected` as it's susceptible to change as shown below
>
> [GHSA-jfh8-c2jp-5v3q (as on 17-Mar-2023)](https://web.archive.org/web/20230317090918/https://deps.dev/_/advisory/osv/GHSA-jfh8-c2jp-5v3q)
> ```json
> "affected": "{[0.alpha:2.3.1),[2.4:2.12.2),[2.13:2.15)}"
> "rawAffected": "Introduced: 2.13.0, Fixed: 2.15.0, Introduced: 0, Fixed: 2.3.1, Introduced: 2.4, Fixed: 2.12.2"
> ```
>
> [GHSA-jfh8-c2jp-5v3q (as on 22-Dec-2022)](https://web.archive.org/web/20221216222510/https://deps.dev/_/advisory/GHSA/GHSA-jfh8-c2jp-5v3q)
> ```json
> "affected": "{[2.4:2.12.2),[0.alpha:2.3.1),[2.13:2.15)}",
> "rawAffected": ">= 2.4, < 2.12.2 or < 2.3.1 or >= 2.13.0, < 2.15.0",
> ```

Contributor guide

No contributing guide indexed for this repository

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.