google/osv.dev

vulnfeeds: detect when version range has introduced > fixed

Open

#215 opened on Sep 1, 2021

View on GitHub
 (5 comments) (0 reactions) (0 assignees)Go (339 forks)auto 404
buggood first issuevulnfeeds

Repository metrics

Stars
 (2,810 stars)
PR merge metrics
 (PR metrics pending)

Description

For PyPI vulnfeeds, there are some cases of bad data in the form of:

introduced: 1.0
fixed: 1.0b4

Encoded like so, this means that everything after and including 1.0 is affeted (because 1.0b4 comes before 1.0). This should instead be something like

introduced: 1.0a0
fixed: 1.0b4

We need to detect these cases in the vulnfeeds tool.

Contributor guide