Skip to content

feat(vulnfeeds): group extracted_events provenance with source, strategy, and ref tags - #6063

Open
jess-lowe wants to merge 15 commits into
google:masterfrom
jess-lowe:refactor/provenance
Open

jess-lowe wants to merge 15 commits into
google:masterfrom
jess-lowe:refactor/provenance

Conversation

@jess-lowe

Copy link
Copy Markdown
Contributor

Merges the provenance improvements from #5820 into the strategy-based CVE5 extraction architecture (refactor/provenance) and extends range provenance with strategy-level attribution. Should be merged after #5971

The best place to observe the changes is probably the snapshots.

Changes

  • Reference Commit vs. Tag Provenance:

    • Added REFERENCES_COMMIT (VersionSourceRefsCommit) and REFERENCES_TAG (VersionSourceRefsTag) sources to differentiate direct commit URLs from GitHub release tag URLs resolved to commits.
    • Extended AffectedCommit and Metadata with Source, Strategy, and OriginalTag fields.
    • Updated Commit() and ExtractGitCommit() to propagate the resolved VersionSource and OriginalTag.
    • Wired reference commit extraction (ExtractCommitsFromRefs) into DefaultVersionExtractor.ExtractVersions.
  • Strategy-Level Attribution:

    • Added ExtractionState.SetStrategyFrom so ExtractAffectedRanges and CPEVersionStrategy automatically tag extracted ranges with the VersionStrategy name (Metadata.Strategy, e.g. StandardRange, SplitRange, StringRangeExpression, StandaloneSingleVersion, CPEApplicability, CPEVersionString).
  • Grouped extracted_events & Direct Git Range Provenance:

    • Restructured database_specific.extracted_events across GitVersionsToCommits, ProcessRanges (including direct Git commit ranges), CreateUnresolvedRanges, and MergeRangesAndCreateAffected to group each extracted range with its provenance metadata (range, source, strategy, cpe, original_tag).
    • Updated combine-to-osv (parseExtractedEvent, parseExtractedEvents, isCPERange) to parse the grouped extracted_events structure while maintaining backward compatibility.
    • Updated unit tests and regenerated cve5 and nvd snapshots.

jess-lowe and others added 15 commits September 2, 2026 22:46
…ted-level contract

Refactor VersionStrategy from a per-version interface with numeric priorities to a slice-ordered, Affected-level contract using ExtractionState to atomically track consumed version entries and prevent duplicate extractions. Also unify CPE fallback extraction across cpeApplicability and affected[].cpes, memoize per-repo version tag resolution in ProcessRanges, and fix Linux conversion outcome counting in AddAffected.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant