Skip to content

Keep the comparator from last_known_affected_version_range - #2455

Open
arpitjain099 wants to merge 1 commit into
aboutcode-org:mainfrom
arpitjain099:fix/keep-last-known-affected-comparator
Open

arpitjain099 wants to merge 1 commit into
aboutcode-org:mainfrom
arpitjain099:fix/keep-last-known-affected-comparator

Conversation

@arpitjain099

Copy link
Copy Markdown

get_last_known_affected_version parses GitHub's last_known_affected_version_range into a range and then returns only affected_version_range.constraints[0].version, dropping the comparator. get_version_ranges_constraints puts it back as <=:

affected_constraint = VersionConstraint(comparator="<", version=v_obj)
if db_specific_explicit_last_known:
    affected_constraint = VersionConstraint(
        comparator="<=", version=db_specific_explicit_last_known
    )

The value is usually <=, so most of the time this is a no-op. When GitHub publishes a strict <, the rewrite marks one more version affected than GitHub says. GHSA-x684-96hh-833x is an example: the API gives >= 5.0.0-RC1, < 5.5.5 and this produces vers:composer/>=5.0.0-RC1|<=5.5.5, so Craft CMS 5.5.5, a real release that is not affected, is reported as affected.

The second entry in that same advisory comes out right, because it has no last_known_affected_version_range and takes the plain < path.

Now the helper returns the whole VersionConstraint and the caller uses it as parsed. I counted the GHSA corpus while looking at this: of 1916 affected entries carrying a last_known_affected_version_range, 1755 are <= and unaffected by this, 161 are a strict <, and 106 of those are in an ecosystem github_osv_importer_v2 imports.

Two cases added to test_osv_v2.py: the helper keeps < and <= as published, and get_version_ranges_constraints carries a strict bound through. Both fail on main, 20 pass here, black and isort clean.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant