Skip to content

fix(purl): filter recommend report vulns to fixed/not_affected only [Backport release/0.6.z] - #2728

Merged
ruromero merged 3 commits into
release/0.6.zfrom
backport-2727-to-release/0.6.z
Oct 1, 2026
Merged

ruromero merged 3 commits into
release/0.6.zfrom
backport-2727-to-release/0.6.z

Conversation

@trustify-ci-bot

@trustify-ci-bot trustify-ci-bot Bot commented Oct 1, 2026 •

Copy link
Copy Markdown

Description

Backport of #2727 to release/0.6.z.

Summary by Sourcery

Filter PURL recommendation reports to show only remediated vulnerabilities and exclude packages without an addressable CVE.

Bug Fixes:

  • Filter recommendation reports to vulnerabilities addressed by the recommended PURL, including only fixed and not_affected statuses.
  • Exclude packages with no fixed or not_affected vulnerabilities from recommendation reports.

Enhancements:

  • Align advisory selection and vulnerability counts with addressed vulnerabilities only.

Tests:

  • Expand recommendation report coverage for mixed vulnerability statuses and packages with no addressable vulnerabilities.
The report's vulnerabilities[] was showing CVEs where the recommended
PURL was affected — misleading users into thinking those CVEs were
addressed. Now only CVEs where the recommended PURL has fixed or
not_affected VEX status are included. Packages with zero addressed
CVEs are excluded from the report entirely.

Implements TC-6683

Assisted-by: Claude Code
(cherry picked from commit 9898d5d)
CSAF ingestion validates CVE IDs match ^CVE-[0-9]{4}-[0-9]{4,}$.
Test IDs like CVE-TEST-FIXED passed locally (lenient parsing) but
failed in CI. Use CVE-2024-9000x format instead.

Implements TC-6683

Assisted-by: Claude Code
(cherry picked from commit 21b888b)
advisory_id was selected from all best_by_vuln entries, so a newer
advisory reporting a CVE as affected could become provenance for a
package whose displayed vulns come from an older fixed advisory.
Now advisory_id is filtered to fixed/not_affected statuses, matching
the vulnerabilities list.

Implements TC-6683

Assisted-by: Claude Code
(cherry picked from commit e8ea4ed)
@sourcery-ai

sourcery-ai Bot commented Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

Reviewer's Guide

The recommendation report now represents remediation candidates rather than active findings: it includes only CVEs marked fixed or not_affected for the recommended PURL, omits packages with no addressed CVEs, and derives advisory metadata and counts from the filtered set. Endpoint tests were updated and expanded to validate mixed statuses, exclusion behavior, and report counts.

Flow diagram for filtered PURL recommendation vulnerabilities

flowchart TD
    A[Recommended PURL vulnerability advisories] --> B[Select best advisory per vulnerability]
    B --> C{Status is fixed or not_affected?}
    C -->|Yes| D[Include CVE in remediation candidates]
    C -->|No| E[Exclude affected or under_investigation CVE]
    D --> F{Any addressed CVEs?}
    F -->|Yes| G[Derive advisory metadata and counts from filtered set]
    F -->|No| H[Omit package from recommendation report]
Loading

File-Level Changes

Change Details Files
Filter recommendation report vulnerabilities to CVEs addressed by the recommended PURL.
  • Retain only fixed and not_affected vulnerability statuses.
  • Exclude packages with no addressed vulnerabilities.
  • Select the advisory ID from addressed vulnerabilities only.
modules/fundamental/src/purl/service/mod.rs
Update and expand recommendation report coverage for addressed and unaddressed vulnerability statuses.
  • Revise the existing test to expect fixed/not-affected CVEs.
  • Add mixed-status coverage verifying affected CVEs are omitted and counts are filtered.
  • Add coverage ensuring packages with only affected CVEs are excluded.
  • Add a reusable minimal CSAF VEX fixture builder.
modules/fundamental/src/purl/endpoints/test.rs

Tips and commands

Interacting with Sourcery

  • Trigger a new review: Comment @sourcery-ai review on the pull request.
  • Continue discussions: Reply directly to Sourcery's review comments.
  • Generate a GitHub issue from a review comment: Ask Sourcery to create an
    issue from a review comment by replying to it. You can also reply to a
    review comment with @sourcery-ai issue to create an issue from it.
  • Generate a pull request title: Write @sourcery-ai anywhere in the pull
    request title to generate a title at any time. You can also comment
    @sourcery-ai title on the pull request to (re-)generate the title at any time.
  • Generate a pull request summary: Write @sourcery-ai summary anywhere in
    the pull request body to generate a PR summary at any time exactly where you
    want it. You can also comment @sourcery-ai summary on the pull request to
    (re-)generate the summary at any time.
  • Generate reviewer's guide: Comment @sourcery-ai guide on the pull
    request to (re-)generate the reviewer's guide at any time.
  • Resolve all Sourcery comments: Comment @sourcery-ai resolve on the
    pull request to resolve all Sourcery comments. Useful if you've already
    addressed all the comments and don't want to see them anymore.
  • Dismiss all Sourcery reviews: Comment @sourcery-ai dismiss on the pull
    request to dismiss all existing Sourcery reviews. Especially useful if you
    want to start fresh with a new review - don't forget to comment
    @sourcery-ai review to trigger a new review!

Customizing Your Experience

Access your dashboard to:

  • Enable or disable review features such as the Sourcery-generated pull request
    summary, the reviewer's guide, and others.
  • Change the review language.
  • Add, remove or edit custom review instructions.
  • Adjust other review settings.

Getting Help

@sourcery-ai sourcery-ai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Hey - I've reviewed your changes and they look great!

Sourcery assessment

Needs a human reviewer. This changes which CVEs appear in remediation reports, excluding affected or under-investigation vulnerabilities and potentially causing consumers to miss required fixes if the status selection is wrong. Reverting restores the previous report behavior, but remediation decisions made from an incorrect report are not automatically undone.


Sourcery is free for open source - if you like our reviews please consider sharing them ✨
@ruromero
ruromero enabled auto-merge October 1, 2026 11:01
@ruromero
ruromero added this pull request to the merge queue Oct 1, 2026
Merged via the queue into release/0.6.z with commit d17fd63 Oct 1, 2026
9 checks passed
@ruromero
ruromero deleted the backport-2727-to-release/0.6.z branch October 1, 2026 11:42
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

1 participant