fix(purl): filter recommend report vulns to fixed/not_affected only - #2727
Conversation
Reviewer's GuideThe recommend report now presents only vulnerabilities resolved or explicitly not affecting the recommended PURL, omits packages with no such CVEs, and keeps package, SBOM, and impact-summary counts consistent with the filtered results. Tests add coverage for mixed statuses and fully unaddressed packages. Flow diagram for filtering recommend report vulnerabilitiesflowchart TD
A[Build best advisory status per CVE] --> B{Status is fixed or not_affected?}
B -->|Yes| C[Include CVE in vulnerabilities]
B -->|No| D[Exclude CVE]
C --> E{Any vulnerabilities remain?}
E -->|Yes| F[Include package in report]
E -->|No| G[Exclude package from report]
F --> H[Update SBOM and impact summary counts]
G --> H
File-Level Changes
Tips and commandsInteracting with Sourcery
Customizing Your ExperienceAccess your dashboard to:
Getting Help
|
There was a problem hiding this comment.
Hey - I've found 1 issue
Prompt for AI Agents
Please address the comments from this code review:
## Individual Comments
### Comment 1
<location path="modules/fundamental/src/purl/service/mod.rs" line_range="1168-1170" />
<code_context>
- "affected" | "under_investigation"
- )
- })
+ .filter(|(_, info)| matches!(info.status_slug.as_str(), "fixed" | "not_affected"))
.map(|(id, _)| id.to_string())
.collect();
</code_context>
<issue_to_address>
**issue (broader_impact):** `advisory_id` is still selected from the most recent advisory across all vulnerabilities, including vulnerabilities filtered out because their status is `affected` or `under_investigation`. A package can therefore list only addressed CVEs while its provenance points to an advisory for an excluded CVE, misleading consumers about which advisory supports the recommendation.
**Triggers:** When an excluded vulnerability has a newer advisory than the fixed or not_affected vulnerabilities retained in the report.
**Suggested fix:** Select `advisory_id` from the retained addressed statuses, or otherwise ensure the selected advisory corresponds to at least one CVE in `vulnerabilities`.
```suggestion
// Advisory ID from the most recent advisory among addressed vulnerabilities.
let advisory_id = best_by_vuln
.values()
.filter(|info| matches!(info.status_slug.as_str(), "fixed" | "not_affected"))
.max_by(|a, b| a.advisory_date.cmp(&b.advisory_date))
.and_then(|info| info.advisory_id.clone());
```
</issue_to_address>Sourcery assessment
Approval pending. 1 finding to address first.
Blocking findings: modules/fundamental/src/purl/service/mod.rs:1170
Verification Report for TC-6683 (commit 859da6a)
Overall: WARNCI checks still pending (windows, bench, test). No failures. All acceptance criteria met, all tests pass locally. This comment was AI-generated by sdlc-workflow/verify-pr v0.13.9. |
The report's vulnerabilities[] was showing CVEs where the recommended PURL was affected — misleading users into thinking those CVEs were addressed. Now only CVEs where the recommended PURL has fixed or not_affected VEX status are included. Packages with zero addressed CVEs are excluded from the report entirely. Implements TC-6683 Assisted-by: Claude Code
CSAF ingestion validates CVE IDs match ^CVE-[0-9]{4}-[0-9]{4,}$.
Test IDs like CVE-TEST-FIXED passed locally (lenient parsing) but
failed in CI. Use CVE-2024-9000x format instead.
Implements TC-6683
Assisted-by: Claude Code
rh-jfuller
left a comment
There was a problem hiding this comment.
new filter limits vulnerabilities to fixed/not_affected but I think advisory_id is still selected from all best_by_vuln entries. If a newer advisory reports another CVE as affected, the package can list an older fixed CVE while naming the newer advisory as its provenance. Maybe select advisory from the statuses that contributed to the filtered list ?
otherwise LGTM
Very good observation. I'll make the suggested change. |
advisory_id was selected from all best_by_vuln entries, so a newer advisory reporting a CVE as affected could become provenance for a package whose displayed vulns come from an older fixed advisory. Now advisory_id is filtered to fixed/not_affected statuses, matching the vulnerabilities list. Implements TC-6683 Assisted-by: Claude Code
|
[sdlc-workflow/verify-pr] Re: @rh-jfuller review — Classified as code change request — advisory_id scoping to addressed (fixed/not_affected) statuses. Already addressed in commit 6929ad1. No sub-task created. |
Verification Report for TC-6683 (commit 6929ad1)
Overall: PASSAll checks pass. Reviewer feedback (advisory_id scoping) addressed. Two approvals (rh-jfuller, sourcery-ai). Ready to merge. This comment was AI-generated by sdlc-workflow/verify-pr v0.13.9. |
|
Successfully created backport PR for |
|
/perf-test |
Summary
RecommendReportPackage.vulnerabilities[]to only include CVEs where the recommended PURL hasfixedornot_affectedVEX statusimpact_summary.addressable_packagesand per-SBOM counts to reflect filtered resultsImplements TC-6683
Test plan
cargo clippyandcargo fmt --checkpasscargo xtask precommitpasses🤖 Generated with Claude Code
Summary by Sourcery
Report only remediable vulnerabilities and omit packages that address none.
Bug Fixes:
Tests: