Skip to content

fix(vulnfeeds): minor outcomes and regex improvements - #6062

Draft
jess-lowe wants to merge 15 commits into
google:masterfrom
jess-lowe:fix/minor-outcome
Draft

jess-lowe wants to merge 15 commits into
google:masterfrom
jess-lowe:fix/minor-outcome

Conversation

@jess-lowe

Copy link
Copy Markdown
Contributor

blocked by #5971

  1. Extract Commits & Release Tags from References in CVE5 (default_extractor.go)

    • Added fallback extraction calling ExtractCommitsFromRefs) across CNA and ADP references when gotVersions is still false, passing resolved commits into MergeRangesAndCreateAffected instead of nil.
  2. Expand Prose Version & Git Commit Extraction versions.go & common.go

    • Leading / infix relative phrases: Added support for prior to, earlier than, up to (and including), fixed/patched/resolved in, and version(s) <= / <, and fixed "through" (and other inclusive keywords) to emit last_affected instead of fixed when validVersions == nil.
    • Trailing inclusive bounds: Added support for <version> and (earlier|before|below|prior|older) (e.g., "Koha 25.11 and before", "SendPortal 3.0.1 and earlier").
    • Prose Git Commit SHAs: Added extraction for (before|prior to|fixed in) commit <sha>, (through|up to|at|in) commit <sha>, and <sha> (is vulnerable|contains a|has a) into Range_GIT ranges, and updated IsDirectGitRange to accept 7–64 character hex SHAs when Range.Type == Range_GIT.
  3. Unaffected-Only / defaultStatus: "affected" Handling inverse_range.go & presets.go

    • Updated FindInverseAffectedRanges to prepend "0" to introduced when defaultStatus == "affected" and only unaffected cutoff versions (including lessThan: "*") are provided, and added InverseAffectedRangesStrategy and VersionTextExtractionStrategy to the Default() and MITRE() presets.
  4. Outcome Upgrade Fix models/metrics.go

    • Fixed SetOutcome so that SetOutcome(Successful) upgrades an earlier NoCommitRanges / NoRanges outcome when a subsequent fallback strategy succeeds.

jess-lowe and others added 15 commits September 2, 2026 22:46
…ted-level contract

Refactor VersionStrategy from a per-version interface with numeric priorities to a slice-ordered, Affected-level contract using ExtractionState to atomically track consumed version entries and prevent duplicate extractions. Also unify CPE fallback extraction across cpeApplicability and affected[].cpes, memoize per-repo version tag resolution in ProcessRanges, and fix Linux conversion outcome counting in AddAffected.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant