Skip to content

Releases: gcve-eu/gcve-lab-patch2vuln

patch2vuln v1.2.0 released with many new features and bugs fixed

Choose a tag to compare

@adulau adulau released this 01 Oct 09:45
v1.2.0
f9cb4ce

patch2vuln is a command-line tool that turns a git-format patch into a structured draft vulnerability advisory using a locally hosted Ollama model.

What's Changed

  • Reject non-patch input before LLM analysis by @adulau in #15
  • Accept commit subjects as credit evidence by @adulau in #16
  • Add CPE 2.3 application identifiers and cpeApplicability to CVE affected entries by @adulau in #17
  • Avoid misleading CPEs for unknown product identities by @adulau in #18
  • Add SSVC assessments across advisory formats by @adulau in #19
  • Add GCVE BCP-05-X-03 vulnerability timeline extension (enabled by default) by @adulau in #20
  • Align SSVC output with the official interchange schema by @adulau in #21

Full Changelog: v1.1.0...v1.2.0

patch2vuln v1.1.0 released including OSV and CSAF support, CVSS output fixed

Choose a tag to compare

@adulau adulau released this 22 Sep 09:11
v1.1.0
fcd3234

What's Changed

  • Add optional CSAF 2.1 complementary output, CLI flags, and tests by @adulau in #11
  • Add optional complementary OSV output by @adulau in #12
  • Add ID-based all-formats output option (--all-formats-output) by @adulau in #13

Full Changelog: v1.0.0...v1.1.0