Skip to content

feat(debian): emit fixed ins for version 0 records#1137

Open
willmurphyscode wants to merge 1 commit intoanchore:mainfrom
willmurphyscode:feat-debian-naks
Open

feat(debian): emit fixed ins for version 0 records#1137
willmurphyscode wants to merge 1 commit intoanchore:mainfrom
willmurphyscode:feat-debian-naks

Conversation

@willmurphyscode
Copy link
Copy Markdown
Contributor

Previously, the Debian provider would drop records where upstream data indicated a package was fixed at "version 0", since these records could never result in a vulnerability match in grype. However, this left downstream providers unable to distinguish between a "search miss" (upstream data has no mention of this CVE/package/distro version tuple) and an explicit indication of "not affected" (Debian maintainers believe this CVE/package/distro version tuple is not affected).

Instead, forward the idea of "fixed at version 0" into the results, so that downstream consumers can distinguish between a search miss and a package that maintainers believe is not affected.

Previously, the Debian provider would drop records where upstream data
indicated a package was fixed at "version 0", since these records could
never result in a vulnerability match in grype. However, this left
downstream providers unable to distinguish between a "search miss"
(upstream data has no mention of this CVE/package/distro version tuple)
and an explicit indication of "not affected" (Debian maintainers believe
this CVE/package/distro version tuple is not affected).

Instead, forward the idea of "fixed at version 0" into the results, so
that downstream consumers can distinguish between a search miss and a
package that maintainers believe is not affected.

Signed-off-by: Will Murphy <willmurphyscode@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

enhancement New feature or request

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant