vulnfeeds: infer introduced and fixed versions from a GitHub compare URL
- Dominant language
- Go
- Stars
- 2.9k
- Forks
- 369
- Avg merge
- 1d 17h
- Merged PRs (30d)
- 149
Description
**Is your feature request related to a problem? Please describe.**
There is an opportunity to infer the `introduced` and `fixed` versions from a CVE's reference when it contains a URL like `https://github.com/JSONPath-Plus/JSONPath/compare/v9.0.0...v10.1.0`
**Describe the solution you'd like**
Today, https://github.com/google/osv.dev/blob/068dfb2ce8c8b92bf92fed40ab602c03084d56c4/vulnfeeds/cves/versions.go#L808-L814
prefers to use any commit references as a `fixed` commit over extracting versions and then attempting to map those to a commit.
Potentially before https://github.com/google/osv.dev/blob/068dfb2ce8c8b92bf92fed40ab602c03084d56c4/vulnfeeds/cves/versions.go#L902-L909 this could look for references like `https://github.com/kovidgoyal/kitty/compare/v0.26.1...v0.26.2` and use this as an `introduced`..`fixed` version range.
**Describe alternatives you've considered**
I considered `last_affected` over `fixed`, but given we already make the other assumption about commit references being `fixed`, I figured we might as well double down on it here 😃
**Additional context**
This would help the likes of [CVE-2024-21534](https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2024-21534) convert in an un-analyzed state.
Contributor guide
Assessment
This issue has not been assessed yet.