Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Release 1.6.1 #211

Closed
wants to merge 29 commits into from
Closed

Release 1.6.1 #211

wants to merge 29 commits into from

Conversation

oliverchang
Copy link
Contributor

No description provided.

oliverchang and others added 29 commits May 4, 2023 08:55
- Add `"additionalProperties": false` to help catch invalid fields.
- Validate RFC3339 timestamps.
- Validate CVSS scores.
Signed-off-by: Oliver Chang <oliverchang@users.noreply.github.com>
There is a Haskell Security Response Team which is now in the process of
defining a repository for security advisories, similar to how Rust
handles these. As part of this, we decided to also integrate with OSV
while we set things up. This should close
haskell/security-advisories#4

There are a few more TODOs left in the PR, partially waiting for
haskell/security-advisories#33 (review),
partially waiting for a first pass over the PR. I'll try to fill in as
much as possible before this can get merged.

---------

Signed-off-by: Mihai Maruseac <mihaimaruseac@google.com>
We are in the process of creating/publishing our own CVE feed based on
OSV schema for the [Bitnami catalog](https://bitnami.com/), but we would
like to start the review process for a `Bitnami` ecosystem key. Do not
hesitate to ask any questions you may have.

---------

Signed-off-by: Gonzalo Gomez Gracia <gonzalog@vmware.com>
Adds Bitnami reference to readme file.

---------

Signed-off-by: Gonzalo Gomez Gracia <gonzalog@vmware.com>
This is a first pass at further clarifying the `"last_affected"` field
and addressing #146 and #150.

Preview is available
[here](https://hayleycd.github.io/osv-schema/#requirements)

---------

Signed-off-by: Hayley Denbraver <denbraver@google.com>
Co-authored-by: Chris Bloom <chrisbloom7@github.com>
Signed-off-by: Kurt Seifried <kurt@seifried.org>

Signed-off-by: Kurt Seifried <kurt@seifried.org>
I adjusted the gemfile for the jekyll page to be more inline with the
current GitHub pages documentation and to avoid a breaking change that
was happening locally.

Happy to answer any questions. 

I am running a [GitHub page](https://hayleycd.github.io/osv-schema/)
from my branch, and you can inspect it if you like.

---------

Signed-off-by: Hayley Denbraver <denbraver@google.com>
As discussed in #105 earlier. I'm also using the ecosystem field in
existing advisories:
https://github.com/captn3m0/photon-os-advisories/blob/main/advisories/PHSA-2016-0006.json

Advisories are already published in OSV format:
https://github.com/captn3m0/photon-os-advisories/tree/main/advisories
(And Automated).

I'll get those enriched over time, but this could be merged in the
interim.

Signed-off-by: Nemo <commits@captnemo.in>

Signed-off-by: Nemo <commits@captnemo.in>
Hopefully wraps up #150 and #146 

View rendered example
[here](https://hayleycd.github.io/osv-schema/#last_affected-vs-fixed-example).

Changes were also made to the [affected.ranges.events
fields](https://hayleycd.github.io/osv-schema/#affectedrangesevents-fields)
to bring the formatting into line with the rest of the document. Fields
were being rendered like this: `"last_affected"` where `last_affected`
is preferred.

---------

Signed-off-by: Hayley Denbraver <denbraver@google.com>
- Bump `Pipfile.lock` with current dependencies (this allows
installation)
- rename `osv` to `entry` to avoid shadowing the `osv` import
- add an option to pass in `--query` from the command line to manual set
query parameters

---------

Signed-off-by: Caleb Brown <calebbrown@google.com>
Bumps [grpcio](https://github.com/grpc/grpc) from 1.46.3 to 1.53.0.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/grpc/grpc/releases">grpcio's
releases</a>.</em></p>
<blockquote>
<h2>Release v1.53.0</h2>
<p>This is release 1.53.0 (<a
href="https://github.com/grpc/grpc/blob/master/doc/g_stands_for.md">glockenspiel</a>)
of gRPC Core.</p>
<p>For gRPC documentation, see <a href="https://grpc.io/">grpc.io</a>.
For previous releases, see <a
href="https://github.com/grpc/grpc/releases">Releases</a>.</p>
<p>This release contains refinements, improvements, and bug fixes, with
highlights listed below.</p>
<h2>Core</h2>
<ul>
<li>xDS: fix crash when removing the last endpoint from the last
locality in weighted_target. (<a
href="https://redirect.github.com/grpc/grpc/pull/32592">#32592</a>)</li>
<li>filter stack: pass peer name up via recv_initial_metadata batch. (<a
href="https://redirect.github.com/grpc/grpc/pull/31933">#31933</a>)</li>
<li>[EventEngine] Add advice against blocking work in callbacks. (<a
href="https://redirect.github.com/grpc/grpc/pull/32397">#32397</a>)</li>
<li>[http2] Dont drop connections on metadata limit exceeded. (<a
href="https://redirect.github.com/grpc/grpc/pull/32309">#32309</a>)</li>
<li>xDS: reject aggregate cluster with empty cluster list. (<a
href="https://redirect.github.com/grpc/grpc/pull/32238">#32238</a>)</li>
<li>Fix Python epoll1 Fork Support. (<a
href="https://redirect.github.com/grpc/grpc/pull/32196">#32196</a>)</li>
<li>server: introduce ServerMetricRecorder API and move per-call
reporting from a C++ interceptor to a C-core filter. (<a
href="https://redirect.github.com/grpc/grpc/pull/32106">#32106</a>)</li>
<li>[EventEngine] Add invalid handle types to the public API. (<a
href="https://redirect.github.com/grpc/grpc/pull/32202">#32202</a>)</li>
<li>[EventEngine] Refactoring the EventEngine Test Suite: Part 1. (<a
href="https://redirect.github.com/grpc/grpc/pull/32127">#32127</a>)</li>
<li>xDS: fix WeightedClusters total weight handling. (<a
href="https://redirect.github.com/grpc/grpc/pull/32134">#32134</a>)</li>
</ul>
<h2>C++</h2>
<ul>
<li>Update minimum MSVC version to 2019. (<a
href="https://redirect.github.com/grpc/grpc/pull/32615">#32615</a>)</li>
<li>Use CMake variables for paths in pkg-config files. (<a
href="https://redirect.github.com/grpc/grpc/pull/31671">#31671</a>)</li>
</ul>
<h2>C#</h2>
<ul>
<li>Grpc.Tools: Use x86 protoc binaries on arm64 Windows. (<a
href="https://redirect.github.com/grpc/grpc/pull/32017">#32017</a>)</li>
</ul>
<h2>Python</h2>
<ul>
<li>Support python 3.11 on aarch64. (<a
href="https://redirect.github.com/grpc/grpc/pull/32270">#32270</a>)</li>
<li>Include .pyi file. (<a
href="https://redirect.github.com/grpc/grpc/pull/32268">#32268</a>)</li>
<li>De-experimentalize wait-for-ready. (<a
href="https://redirect.github.com/grpc/grpc/pull/32143">#32143</a>)</li>
<li>De-experimentalize compression. (<a
href="https://redirect.github.com/grpc/grpc/pull/32138">#32138</a>)</li>
</ul>
<h2>Ruby</h2>
<ul>
<li>[ruby]: add pre-compiled binaries for ruby 3.2; drop them for ruby
2.6. (<a
href="https://redirect.github.com/grpc/grpc/pull/32089">#32089</a>)</li>
</ul>
<h2>Release v1.53.0-pre2</h2>
<p>This is a prerelease of gRPC Core 1.53.0 (glockenspiel).</p>
<p>For gRPC documentation, see <a href="https://grpc.io/">grpc.io</a>.
For previous releases, see <a
href="https://github.com/grpc/grpc/releases">Releases</a>.</p>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/grpc/grpc/commit/358bfb581feeda5bf17dd3b96da1074d84a6ef8d"><code>358bfb5</code></a>
Bump version to 1.53.0 (<a
href="https://redirect.github.com/grpc/grpc/issues/32685">#32685</a>)</li>
<li><a
href="https://github.com/grpc/grpc/commit/6e1ebe76d87a2e9b643c08b3e234d374edcd9e92"><code>6e1ebe7</code></a>
Backport: Ensure compatibility with the new custom kokoro win2019 image
(<a
href="https://redirect.github.com/grpc/grpc/issues/326">#326</a>...</li>
<li><a
href="https://github.com/grpc/grpc/commit/44a77f6e911b95e1bc2c909b348123b2da2c4375"><code>44a77f6</code></a>
Backport 1.53: Update minimum MSVC version to 2019 (<a
href="https://redirect.github.com/grpc/grpc/issues/32615">#32615</a>)</li>
<li><a
href="https://github.com/grpc/grpc/commit/c11153cb4ef01ca5f83304b2e28edd0182b3c0d0"><code>c11153c</code></a>
backport to 1.53: xDS: fix crash when removing the last endpoint from
the las...</li>
<li><a
href="https://github.com/grpc/grpc/commit/7c7712a6b08ebf1bdc18fc43dc871b47b3dffe97"><code>7c7712a</code></a>
Bump version to 1.53.0-pre2. (<a
href="https://redirect.github.com/grpc/grpc/issues/32545">#32545</a>)</li>
<li><a
href="https://github.com/grpc/grpc/commit/a4017dc45e342064722a36181ed14e6d7b469d29"><code>a4017dc</code></a>
backport to 1.53: [promises] Make Poll&lt;T&gt; its own type, not a
variant&lt;&gt; (<a
href="https://redirect.github.com/grpc/grpc/issues/32540">#32540</a>)</li>
<li><a
href="https://github.com/grpc/grpc/commit/3f93c1667280e6f11a1eb35cccfb8c81c698bee5"><code>3f93c16</code></a>
Fuzzer fix backport to v1.53 (<a
href="https://redirect.github.com/grpc/grpc/issues/32511">#32511</a>)</li>
<li><a
href="https://github.com/grpc/grpc/commit/5b244b25c2b87a85781ceeecd34ce0f8e8e7e840"><code>5b244b2</code></a>
Bump release version to 1.53.0-pre1 (<a
href="https://redirect.github.com/grpc/grpc/issues/32428">#32428</a>)</li>
<li><a
href="https://github.com/grpc/grpc/commit/6589340efc39b87c94897d221eaf949213cdac87"><code>6589340</code></a>
Bump core version 202302161703 (<a
href="https://redirect.github.com/grpc/grpc/issues/32416">#32416</a>)</li>
<li><a
href="https://github.com/grpc/grpc/commit/d49e1513063e6624e08eb6f59049596178a28783"><code>d49e151</code></a>
[backoff] Add random early detection classifier (<a
href="https://redirect.github.com/grpc/grpc/issues/32354">#32354</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/grpc/grpc/compare/v1.46.3...v1.53.0">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=grpcio&package-manager=pip&previous-version=1.46.3&new-version=1.53.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot merge` will merge this PR after your CI passes on it
- `@dependabot squash and merge` will squash and merge this PR after
your CI passes on it
- `@dependabot cancel merge` will cancel a previously requested merge
and block automerging
- `@dependabot reopen` will reopen this PR if it is closed
- `@dependabot close` will close this PR and stop Dependabot recreating
it. You can achieve the same result by closing it manually
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)
You can disable automated security fix PRs for this repo from the
[Security Alerts
page](https://github.com/ossf/osv-schema/network/alerts).

</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Based on conversation on #168, the CVSS validation by pure regex is too
strict, so remove.

Fixes: #168

Signed-off-by: Andrew Pollock <andrewpollock@users.noreply.github.com>
Closes #175.

I didn't quite understand "Source URL" vs. "OSV Formatted URL" so I took
a guess.

cc @tylfin as upstream maintainer. I marked this as "unofficial" despite
R Consortium backing, please CMIIW.

---------

Signed-off-by: Michael Chirico <michaelchirico4@gmail.com>
Signed-off-by: Oliver Chang <oliverchang@users.noreply.github.com>
Co-authored-by: Tyler Finethy <tylfin@gmail.com>
Co-authored-by: Oliver Chang <oliverchang@users.noreply.github.com>
Also fix OSV formatted URL for RSEC with `vulns` path

Per comment:
#175 (comment)
When dumping GHSA for Malware these values are all "0" and don't make
sense.

---------

Signed-off-by: Caleb Brown <calebbrown@google.com>
Per


https://developer.apple.com/documentation/packagedescription/package/dependency

https://docs.swift.org/package-manager/PackageDescription/PackageDescription.html#package-dependency

Putting "URL" in the name to make this consistent with how it's actually
defined using `Package.Dependency`.

There are some changes coming as part of
https://github.com/apple/swift-evolution/blob/main/proposals/0292-package-registry-service.md,
and we'll likely need to define a new ecosystem for that once it's
finalized, as it looks like the identifiers are moving to a `Scope.Name`
format.

Fixes #170.

---------

Signed-off-by: Oliver Chang <oliverchang@users.noreply.github.com>
Related to: psf/advisory-database#9

Signed-off-by: Seth Michael Larson <seth@python.org>
Clarify the intended use cases for the `aliases` and `related` field to
align with our intended use cases.

Signed-off-by: Michael Kedar <michaelkedar@google.com>
Android package name definition now points to the git project affected
and where the patches should be applied to instead of bulletin
components.

Remove the Android Ecosystem Components appendix.

Signed-off-by: Dory <dory@dory.moe>
Adding Curl to the list of sources. 

Signed-off-by: Oliver Chang <oliverchang@users.noreply.github.com>
As title.

Signed-off-by: Randy Lai <randy.cs.lai@gmail.com>
I had left 2 TODOs to add JSON examples. Filling them now (will redo the
GHC one when we get a real GHC issue) and closing
haskell/security-advisories#4.

---------

Signed-off-by: Mihai Maruseac <mihai.maruseac@gmail.com>
@Roo4L from AlmaLinux suggested we explain why aliases shouldn't be used
for bundling.
I've added a sentence based on their suggestion.

Signed-off-by: Michael Kedar <michaelkedar@google.com>
Add CURL to list of DBs.

Signed-off-by: Oliver Chang <oliverchang@users.noreply.github.com>
Reverts #172. This is already in the list (whoops).
We always want projects/SIGs to point to their working group, but this
one doesn't. Let's fix that, and tweak some other text along the way so
it's clearer for visitors.

Signed-off-by: David A. Wheeler <dwheeler@dwheeler.com>
Signed-off-by: Oliver Chang <oliverchang@users.noreply.github.com>
Co-authored-by: Oliver Chang <oliverchang@users.noreply.github.com>
- Make Purpose section more concise. We don't need a history lesson here
anymore :)
- Remove old changelogs.
- Alphabetically sort databases and ecosystems.
- Add some missing databases (Curl, NVD).

---------

Signed-off-by: Oliver Chang <ochang@google.com>
Signed-off-by: Oliver Chang <oliverchang@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.