fix(purl): filter recommend report vulns to fixed/not_affected only [Backport release/0.6.z] - #2728
Conversation
The report's vulnerabilities[] was showing CVEs where the recommended PURL was affected — misleading users into thinking those CVEs were addressed. Now only CVEs where the recommended PURL has fixed or not_affected VEX status are included. Packages with zero addressed CVEs are excluded from the report entirely. Implements TC-6683 Assisted-by: Claude Code (cherry picked from commit 9898d5d)
CSAF ingestion validates CVE IDs match ^CVE-[0-9]{4}-[0-9]{4,}$.
Test IDs like CVE-TEST-FIXED passed locally (lenient parsing) but
failed in CI. Use CVE-2024-9000x format instead.
Implements TC-6683
Assisted-by: Claude Code
(cherry picked from commit 21b888b)
advisory_id was selected from all best_by_vuln entries, so a newer advisory reporting a CVE as affected could become provenance for a package whose displayed vulns come from an older fixed advisory. Now advisory_id is filtered to fixed/not_affected statuses, matching the vulnerabilities list. Implements TC-6683 Assisted-by: Claude Code (cherry picked from commit e8ea4ed)
Reviewer's GuideThe recommendation report now represents remediation candidates rather than active findings: it includes only CVEs marked fixed or not_affected for the recommended PURL, omits packages with no addressed CVEs, and derives advisory metadata and counts from the filtered set. Endpoint tests were updated and expanded to validate mixed statuses, exclusion behavior, and report counts. Flow diagram for filtered PURL recommendation vulnerabilitiesflowchart TD
A[Recommended PURL vulnerability advisories] --> B[Select best advisory per vulnerability]
B --> C{Status is fixed or not_affected?}
C -->|Yes| D[Include CVE in remediation candidates]
C -->|No| E[Exclude affected or under_investigation CVE]
D --> F{Any addressed CVEs?}
F -->|Yes| G[Derive advisory metadata and counts from filtered set]
F -->|No| H[Omit package from recommendation report]
File-Level Changes
Tips and commandsInteracting with Sourcery
Customizing Your ExperienceAccess your dashboard to:
Getting Help
|
There was a problem hiding this comment.
Hey - I've reviewed your changes and they look great!
Sourcery assessment
Needs a human reviewer. This changes which CVEs appear in remediation reports, excluding affected or under-investigation vulnerabilities and potentially causing consumers to miss required fixes if the status selection is wrong. Reverting restores the previous report behavior, but remediation decisions made from an incorrect report are not automatically undone.
Description
Backport of #2727 to
release/0.6.z.Summary by Sourcery
Filter PURL recommendation reports to show only remediated vulnerabilities and exclude packages without an addressable CVE.
Bug Fixes:
Enhancements:
Tests: