From b9216107f2c600cb032d93530c56e1ae7f16337a Mon Sep 17 00:00:00 2001 From: Arpit Jain Date: Wed, 30 Sep 2026 03:29:24 -0400 Subject: [PATCH] Keep the comparator from last_known_affected_version_range Signed-off-by: Arpit Jain --- vulnerabilities/pipes/osv_v2.py | 12 ++++--- vulnerabilities/tests/pipes/test_osv_v2.py | 37 ++++++++++++++++++++++ 2 files changed, 44 insertions(+), 5 deletions(-) diff --git a/vulnerabilities/pipes/osv_v2.py b/vulnerabilities/pipes/osv_v2.py index 9186c43c0..34c186ebb 100644 --- a/vulnerabilities/pipes/osv_v2.py +++ b/vulnerabilities/pipes/osv_v2.py @@ -397,7 +397,8 @@ def get_explicit_affected_range(affected_pkg, raw_id, supported_ecosystem): def get_last_known_affected_version(affected_pkg, raw_id, supported_ecosystem): """ - Return the last_known_affected_version_range from the database_specific + Return the VersionConstraint parsed from the ``last_known_affected_version_range`` + in the database_specific data, or None. """ database_specific = affected_pkg.get("database_specific") or {} last_known_value = database_specific.get("last_known_affected_version_range") @@ -409,7 +410,7 @@ def get_last_known_affected_version(affected_pkg, raw_id, supported_ecosystem): affected_version_range = build_range_from_github_advisory_constraint( supported_ecosystem, last_known_value ) - return affected_version_range.constraints[0].version + return affected_version_range.constraints[0] except Exception as e: logger.error( @@ -490,9 +491,10 @@ def get_version_ranges_constraints( # version is applicable to all ranges of current affected block. affected_constraint = VersionConstraint(comparator="<", version=v_obj) if db_specific_explicit_last_known: - affected_constraint = VersionConstraint( - comparator="<=", version=db_specific_explicit_last_known - ) + # Keep the comparator GitHub published. It is usually "<=" but a + # strict "<" happens, and rewriting it marks one extra version + # affected that GitHub says is not. + affected_constraint = db_specific_explicit_last_known affected_constraints.append(affected_constraint) diff --git a/vulnerabilities/tests/pipes/test_osv_v2.py b/vulnerabilities/tests/pipes/test_osv_v2.py index a6c3a380c..2623ee67c 100644 --- a/vulnerabilities/tests/pipes/test_osv_v2.py +++ b/vulnerabilities/tests/pipes/test_osv_v2.py @@ -15,10 +15,12 @@ from univers.version_constraint import VersionConstraint from univers.version_range import MavenVersionRange from univers.version_range import PypiVersionRange +from univers.versions import ComposerVersion from univers.versions import MavenVersion from univers.versions import PypiVersion from vulnerabilities.pipes.osv_v2 import get_explicit_affected_range +from vulnerabilities.pipes.osv_v2 import get_last_known_affected_version from vulnerabilities.pipes.osv_v2 import get_version_ranges_constraints from vulnerabilities.pipes.osv_v2 import parse_advisory_data_v3 from vulnerabilities.tests import util_tests @@ -78,6 +80,41 @@ def test_get_version_ranges_constraints(): ) +def test_get_last_known_affected_version_keeps_the_comparator(): + affected_pkg = { + "database_specific": {"last_known_affected_version_range": "< 5.5.5"}, + } + assert get_last_known_affected_version( + affected_pkg=affected_pkg, + raw_id="GHSA-x684-96hh-833x", + supported_ecosystem="composer", + ) == VersionConstraint(comparator="<", version=ComposerVersion(string="5.5.5")) + + affected_pkg["database_specific"]["last_known_affected_version_range"] = "<= 5.5.5" + assert get_last_known_affected_version( + affected_pkg=affected_pkg, + raw_id="GHSA-x684-96hh-833x", + supported_ecosystem="composer", + ) == VersionConstraint(comparator="<=", version=ComposerVersion(string="5.5.5")) + + +def test_get_version_ranges_constraints_keeps_a_strict_last_known_bound(): + # GitHub says "< 5.5.5", so 5.5.5 itself is not affected. + affected, fixed, _, _ = get_version_ranges_constraints( + ranges={"type": "ECOSYSTEM", "events": [{"introduced": "5.0.0-RC1"}, {"fixed": "5.5.5"}]}, + raw_id="GHSA-x684-96hh-833x", + supported_ecosystem="composer", + db_specific_explicit_last_known=VersionConstraint( + comparator="<", version=ComposerVersion(string="5.5.5") + ), + ) + assert affected == [ + VersionConstraint(comparator=">=", version=ComposerVersion(string="5.0.0-RC1")), + VersionConstraint(comparator="<", version=ComposerVersion(string="5.5.5")), + ] + assert fixed == [VersionConstraint(comparator="=", version=ComposerVersion(string="5.5.5"))] + + def test_get_explicit_affected_constraints(): assert get_explicit_affected_range( affected_pkg={