You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
This commit was created on GitHub.com and signed with GitHub’s verified signature.
feat: hot CVE types and version constraint evaluator (SUB-7220) (#630)
* feat: add hot CVE types and version constraint evaluator
Add HotCVE, HotCVEAffectedPackage, HotCVEEndpointResponse, and
HotCVEOnFinishedMessage types for hot CVE detection (SUB-7201).
Add HotCVE field to NotificationParams for UNS integration.
Add VersionConstraint with Matches() for evaluating SBOM components
against affected version ranges, with comprehensive tests.
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
* fix: clarify Compare() inverted semantics in constraint comments
Compare() returns other.Compare(self), not self.Compare(other).
Comments now accurately describe what cmp > 0 and cmp <= 0 mean.
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
* fix: rename CVEId to CVEID — Go initialism convention
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
* fix: use camelCase for all JSON/BSON field tags
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
* remove: drop VersionConstraint — inline logic used in event-ingester instead
Version range matching is done inline in the consuming service.
No need for a separate abstraction for 4-5 uses per year.
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
* feat: add Validate() methods to HotCVE and HotCVEAffectedPackage
Shared validation for use in both cadashboardbe admin API and
event-ingester message handler.
Validates:
- Required fields: cveId, severity, affectedPackages
- Severity values: critical, high, medium, low (case insensitive)
- Status values: active, inactive (or empty)
- Per-package: packageName required, at least one version constraint
- 14 unit tests
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
* fix: use shared severity validation, add JSON example test
- Rename validSeverities → validHotCVESeverities with comment
about containerscan.KnownSeverities (circular dep prevents import)
- Add testdata/hot_cve_example.json with realistic xz backdoor + node.js examples
- Add TestHotCVE_Validate_FromJSON that loads and validates the example
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
* remove: IsRCE field, severity validation, simplify HotCVEOnFinishedMessage
- IsRCE not in requirements, enrichers fill it from NVD
- Severity validation removed — consumers can validate if needed
- HotCVEOnFinishedMessage simplified (removed unused fields)
- Updated JSON example and tests
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>