google / google/osv.dev

vulnfeeds: infer introduced and fixed versions from a GitHub compare URL

Open
#2,924 0 comments 0 reactions 0 assignees View on GitHub
enhancement good first issue vulnfeeds
Dominant language
Go
Stars
2.9k
Forks
369
Avg merge
1d 17h
Merged PRs (30d)
149

Description

**Is your feature request related to a problem? Please describe.**
There is an opportunity to infer the `introduced` and `fixed` versions from a CVE's reference when it contains a URL like `https://github.com/JSONPath-Plus/JSONPath/compare/v9.0.0...v10.1.0`

**Describe the solution you'd like**
Today, https://github.com/google/osv.dev/blob/068dfb2ce8c8b92bf92fed40ab602c03084d56c4/vulnfeeds/cves/versions.go#L808-L814

prefers to use any commit references as a `fixed` commit over extracting versions and then attempting to map those to a commit.

Potentially before https://github.com/google/osv.dev/blob/068dfb2ce8c8b92bf92fed40ab602c03084d56c4/vulnfeeds/cves/versions.go#L902-L909 this could look for references like `https://github.com/kovidgoyal/kitty/compare/v0.26.1...v0.26.2` and use this as an `introduced`..`fixed` version range.

**Describe alternatives you've considered**
I considered `last_affected` over `fixed`, but given we already make the other assumption about commit references being `fixed`, I figured we might as well double down on it here 😃

**Additional context**
This would help the likes of [CVE-2024-21534](https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2024-21534) convert in an un-analyzed state.

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.