Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
12 changes: 7 additions & 5 deletions vulnerabilities/pipes/osv_v2.py
Original file line number Diff line number Diff line change
Expand Up @@ -397,7 +397,8 @@ def get_explicit_affected_range(affected_pkg, raw_id, supported_ecosystem):

def get_last_known_affected_version(affected_pkg, raw_id, supported_ecosystem):
"""
Return the last_known_affected_version_range from the database_specific
Return the VersionConstraint parsed from the ``last_known_affected_version_range``
in the database_specific data, or None.
"""
database_specific = affected_pkg.get("database_specific") or {}
last_known_value = database_specific.get("last_known_affected_version_range")
Expand All @@ -409,7 +410,7 @@ def get_last_known_affected_version(affected_pkg, raw_id, supported_ecosystem):
affected_version_range = build_range_from_github_advisory_constraint(
supported_ecosystem, last_known_value
)
return affected_version_range.constraints[0].version
return affected_version_range.constraints[0]

except Exception as e:
logger.error(
Expand Down Expand Up @@ -490,9 +491,10 @@ def get_version_ranges_constraints(
# version is applicable to all ranges of current affected block.
affected_constraint = VersionConstraint(comparator="<", version=v_obj)
if db_specific_explicit_last_known:
affected_constraint = VersionConstraint(
comparator="<=", version=db_specific_explicit_last_known
)
# Keep the comparator GitHub published. It is usually "<=" but a
# strict "<" happens, and rewriting it marks one extra version
# affected that GitHub says is not.
affected_constraint = db_specific_explicit_last_known

affected_constraints.append(affected_constraint)

Expand Down
37 changes: 37 additions & 0 deletions vulnerabilities/tests/pipes/test_osv_v2.py
Original file line number Diff line number Diff line change
Expand Up @@ -15,10 +15,12 @@
from univers.version_constraint import VersionConstraint
from univers.version_range import MavenVersionRange
from univers.version_range import PypiVersionRange
from univers.versions import ComposerVersion
from univers.versions import MavenVersion
from univers.versions import PypiVersion

from vulnerabilities.pipes.osv_v2 import get_explicit_affected_range
from vulnerabilities.pipes.osv_v2 import get_last_known_affected_version
from vulnerabilities.pipes.osv_v2 import get_version_ranges_constraints
from vulnerabilities.pipes.osv_v2 import parse_advisory_data_v3
from vulnerabilities.tests import util_tests
Expand Down Expand Up @@ -78,6 +80,41 @@ def test_get_version_ranges_constraints():
)


def test_get_last_known_affected_version_keeps_the_comparator():
affected_pkg = {
"database_specific": {"last_known_affected_version_range": "< 5.5.5"},
}
assert get_last_known_affected_version(
affected_pkg=affected_pkg,
raw_id="GHSA-x684-96hh-833x",
supported_ecosystem="composer",
) == VersionConstraint(comparator="<", version=ComposerVersion(string="5.5.5"))

affected_pkg["database_specific"]["last_known_affected_version_range"] = "<= 5.5.5"
assert get_last_known_affected_version(
affected_pkg=affected_pkg,
raw_id="GHSA-x684-96hh-833x",
supported_ecosystem="composer",
) == VersionConstraint(comparator="<=", version=ComposerVersion(string="5.5.5"))


def test_get_version_ranges_constraints_keeps_a_strict_last_known_bound():
# GitHub says "< 5.5.5", so 5.5.5 itself is not affected.
affected, fixed, _, _ = get_version_ranges_constraints(
ranges={"type": "ECOSYSTEM", "events": [{"introduced": "5.0.0-RC1"}, {"fixed": "5.5.5"}]},
raw_id="GHSA-x684-96hh-833x",
supported_ecosystem="composer",
db_specific_explicit_last_known=VersionConstraint(
comparator="<", version=ComposerVersion(string="5.5.5")
),
)
assert affected == [
VersionConstraint(comparator=">=", version=ComposerVersion(string="5.0.0-RC1")),
VersionConstraint(comparator="<", version=ComposerVersion(string="5.5.5")),
]
assert fixed == [VersionConstraint(comparator="=", version=ComposerVersion(string="5.5.5"))]


def test_get_explicit_affected_constraints():
assert get_explicit_affected_range(
affected_pkg={
Expand Down