Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

feat: create versioned purls from OSV #897

Closed
wants to merge 1 commit into from
Closed
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
153 changes: 72 additions & 81 deletions modules/ingestor/src/service/advisory/osv/loader.rs
Original file line number Diff line number Diff line change
Expand Up @@ -4,6 +4,7 @@ use crate::{
advisory_vulnerability::{Version, VersionInfo, VersionSpec},
AdvisoryInformation, AdvisoryVulnerabilityInformation,
},
purl::creator::PurlCreator,
Graph,
},
model::IngestResult,
Expand Down Expand Up @@ -70,6 +71,8 @@ impl<'g> OsvLoader<'g> {
.await?;
}

let mut purl_creator = PurlCreator::new();

for cve_id in cve_ids {
self.graph.ingest_vulnerability(&cve_id, (), &tx).await?;

Expand Down Expand Up @@ -104,97 +107,85 @@ impl<'g> OsvLoader<'g> {
}

for affected in &osv.affected {
if let Some(package) = &affected.package {
let mut purls = vec![];
// we only process it when we have a package
ctron marked this conversation as resolved.
Show resolved Hide resolved

let Some(package) = &affected.package else {
continue;
};

purls.extend(translate::to_purl(package).map(Purl::from));
// extract PURLs

let mut purls = vec![];
purls.extend(translate::to_purl(package).map(Purl::from));
Copy link
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

is this some kind of hyper specific translate to purl ?

Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Yup.

if let Some(purl) = &package.purl {
purls.extend(Purl::from_str(purl).ok());
}

if let Some(purl) = &package.purl {
purls.extend(Purl::from_str(purl).ok());
for purl in purls {
// iterate through the known versions, apply the version, and create them
for version in affected.versions.iter().flatten() {
let mut purl = purl.clone();
purl.version = Some(version.clone());
purl_creator.add(purl);
}

for purl in purls {
for range in affected.ranges.iter().flatten() {
let parsed_range = events_to_range(&range.events);
match &parsed_range {
(Some(start), None) => {
advisory_vuln
.ingest_package_status(
None,
&purl,
"affected",
VersionInfo {
// TODO detect better version scheme
scheme: "semver".to_string(),
spec: VersionSpec::Range(
Version::Inclusive(start.clone()),
Version::Unbounded,
),
},
&tx,
)
.await?
}
(None, Some(end)) => {
advisory_vuln
.ingest_package_status(
None,
&purl,
"affected",
VersionInfo {
// TODO detect better version scheme
scheme: "semver".to_string(),
spec: VersionSpec::Range(
Version::Unbounded,
Version::Exclusive(end.clone()),
),
},
&tx,
)
.await?
}
(Some(start), Some(end)) => {
advisory_vuln
.ingest_package_status(
None,
&purl,
"affected",
VersionInfo {
// TODO detect better version scheme
scheme: "semver".to_string(),
spec: VersionSpec::Range(
Version::Inclusive(start.clone()),
Version::Exclusive(end.clone()),
),
},
&tx,
)
.await?
}
_ => { /* what? */ }
}

if let (_, Some(fixed)) = &parsed_range {
advisory_vuln
.ingest_package_status(
None,
&purl,
"fixed",
VersionInfo {
// TODO detect better version scheme
scheme: "semver".to_string(),
spec: VersionSpec::Exact(fixed.clone()),
},
&tx,
)
.await?
}
for range in affected.ranges.iter().flatten() {
let parsed_range = events_to_range(&range.events);

let spec = match &parsed_range {
(Some(start), None) => Some(VersionSpec::Range(
Version::Inclusive(start.clone()),
Version::Unbounded,
)),
(None, Some(end)) => Some(VersionSpec::Range(
Version::Unbounded,
Version::Exclusive(end.clone()),
)),
(Some(start), Some(end)) => Some(VersionSpec::Range(
Version::Inclusive(start.clone()),
Version::Exclusive(end.clone()),
)),
(None, None) => None,
};

if let Some(spec) = spec {
advisory_vuln
.ingest_package_status(
None,
&purl,
"affected",
VersionInfo {
// TODO detect better version scheme
scheme: "semver".to_string(),
spec,
},
&tx,
)
.await?;
}

if let (_, Some(fixed)) = &parsed_range {
advisory_vuln
.ingest_package_status(
None,
&purl,
"fixed",
VersionInfo {
// TODO detect better version scheme
ctron marked this conversation as resolved.
Show resolved Hide resolved
scheme: "semver".to_string(),
spec: VersionSpec::Exact(fixed.clone()),
},
&tx,
)
.await?
}
}
}
}
}

purl_creator.create(&self.graph.connection(&tx)).await?;

tx.commit().await?;

Ok(IngestResult {
Expand Down