Description
Improve performance by removing/reducing redundant regex.
Based on issue #5840
Explanation
1. Common RPM package version string pattern
Common RPM package version string pattern, in the form ;
{"type":"rpm","name":"gawk","version":"5.1.1-5.fc38","architecture":"x86_64","osCpe":"cpe:/o:fedoraproject:fedora:38"}
Instead of having it in many (all ?) checkers, we should have it running once, identifying the package name and its version.
2. Simple version string
Many version string patterns actually have formats like:
(<prog_name>)(?: version |[ /])(<version>)
([a-zA-Z]+)(?: version |[ \/])(\d+(?:\.\d+){2,4})
Guile 2.2.7
Lua 5.0.3
GNU PSPP 1.4.0
Varnish 7.7.3
radmin version 2.2.10
libpng version 1.6.26
LibreOffice/7.0.1.2
CUPS/2.2.9
Such as in the previous one: instead of having it in many checkers, we should have it running once, identifying the package name and its version.
- Note: It would suppose that we are able to convert
prog_name into the actual package name used for CVE reporting, which might be slightly different.
Why?
To improve scanner scanning performance and capabilities (detect more accurately)
Description
Improve performance by removing/reducing redundant regex.
Based on issue #5840
Explanation
1. Common RPM package version string pattern
Common RPM package version string pattern, in the form ;
{"type":"rpm","name":"gawk","version":"5.1.1-5.fc38","architecture":"x86_64","osCpe":"cpe:/o:fedoraproject:fedora:38"}Instead of having it in many (all ?) checkers, we should have it running once, identifying the package name and its version.
2. Simple version string
Many version string patterns actually have formats like:
Such as in the previous one: instead of having it in many checkers, we should have it running once, identifying the package name and its version.
prog_nameinto the actual package name used for CVE reporting, which might be slightly different.Why?
To improve scanner scanning performance and capabilities (detect more accurately)