Skip to content

Release v0.0.697

Choose a tag to compare

@github-actions github-actions released this 15 Apr 07:18
80e9cbe
feat: hot CVE types and version constraint evaluator (SUB-7220) (#630)

* feat: add hot CVE types and version constraint evaluator

Add HotCVE, HotCVEAffectedPackage, HotCVEEndpointResponse, and
HotCVEOnFinishedMessage types for hot CVE detection (SUB-7201).
Add HotCVE field to NotificationParams for UNS integration.
Add VersionConstraint with Matches() for evaluating SBOM components
against affected version ranges, with comprehensive tests.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>

* fix: clarify Compare() inverted semantics in constraint comments

Compare() returns other.Compare(self), not self.Compare(other).
Comments now accurately describe what cmp > 0 and cmp <= 0 mean.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>

* fix: rename CVEId to CVEID — Go initialism convention

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>

* fix: use camelCase for all JSON/BSON field tags

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>

* remove: drop VersionConstraint — inline logic used in event-ingester instead

Version range matching is done inline in the consuming service.
No need for a separate abstraction for 4-5 uses per year.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>

* feat: add Validate() methods to HotCVE and HotCVEAffectedPackage

Shared validation for use in both cadashboardbe admin API and
event-ingester message handler.

Validates:
- Required fields: cveId, severity, affectedPackages
- Severity values: critical, high, medium, low (case insensitive)
- Status values: active, inactive (or empty)
- Per-package: packageName required, at least one version constraint
- 14 unit tests

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>

* fix: use shared severity validation, add JSON example test

- Rename validSeverities → validHotCVESeverities with comment
  about containerscan.KnownSeverities (circular dep prevents import)
- Add testdata/hot_cve_example.json with realistic xz backdoor + node.js examples
- Add TestHotCVE_Validate_FromJSON that loads and validates the example

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>

* remove: IsRCE field, severity validation, simplify HotCVEOnFinishedMessage

- IsRCE not in requirements, enrichers fill it from NVD
- Severity validation removed — consumers can validate if needed
- HotCVEOnFinishedMessage simplified (removed unused fields)
- Updated JSON example and tests

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>