Support Advisory Comparison in VulnTotal - #1151
Merged
Merged
Conversation
Member
Author
Preview❯ vulntotal "pkg:pypi/jinja2@2.4.1" --vers -e github -e vulnerablecode -e safetydb
PURL: pkg:pypi/jinja2@2.4.1
Active DataSources: GITHUB, SAFETYDB, VULNERABLECODE
+-----------------+---------------+---------------+--------------------+--------------------+--------+
| CVE | DATASOURCE | ALIASES | AFFECTED | FIXED | SCORE |
+=================+===============+===============+====================+====================+========+
| CVE-2024-22195 | VULNERABLECOD | CVE-2024- | 2.0 2.0rc1 2.1 | 3.1.3 | 100 |
| | E | 22195 | 2.10 2.10.1 | | |
| | | GHSA-h5c8- | 2.10.2 2.10.3 | | |
| | | rqwp-cp95 | 2.1.1 2.11.0 | | |
| | | | 2.11.1 2.11.2 | | |
| | | | 2.11.3 2.2 2.2.1 | | |
| | | | 2.3 2.3.1 2.4 | | |
| | | | 2.4.1 2.5 2.5.1 | | |
| | | | 2.5.2 2.5.3 | | |
| | | | 2.5.4 2.5.5 2.6 | | |
| | | | 2.7 2.7.1 2.7.2 | | |
| | | | 2.7.3 2.8 2.8.1 | | |
| | | | 2.9 2.9.1 2.9.2 | | |
| | | | 2.9.3 2.9.4 | | |
| | | | 2.9.5 2.9.6 | | |
| | | | 3.0.0 3.0.0a1 | | |
| | | | 3.0.0rc1 3.0.0rc2 | | |
| | | | 3.0.1 3.0.2 | | |
| | | | 3.0.3 3.1.0 | | |
| | | | 3.1.1 3.1.2 | | |
+-----------------+---------------+---------------+--------------------+--------------------+--------+
| | | | vers:pypi/>=2.0rc1 | vers:pypi/3.1.3 | |
| | | | |<=3.1.2 | | |
+-----------------+---------------+---------------+--------------------+--------------------+--------+
| CVE-2024-22195 | SAFETYDB | CVE-2024- | <3.1.3 | | 67 |
| | | 22195 | | | |
| | | pyup.io-64227 | | | |
+-----------------+---------------+---------------+--------------------+--------------------+--------+
| | | | vers:pypi/>=2.0rc1 | [] | |
| | | | |<=3.1.2 | | |
+-----------------+---------------+---------------+--------------------+--------------------+--------+
| CVE-2024-22195 | GITHUB | CVE-2024- | < 3.1.3 | 3.1.3 | 100 |
| | | 22195 | | | |
| | | GHSA-h5c8- | | | |
| | | rqwp-cp95 | | | |
+-----------------+---------------+---------------+--------------------+--------------------+--------+
| | | | vers:pypi/>=2.0rc1 | vers:pypi/3.1.3 | |
| | | | |<=3.1.2 | | |
+-----------------+---------------+---------------+--------------------+--------------------+--------+
| CVE-2020-28493 | VULNERABLECOD | CVE-2020- | 2.0 2.0rc1 2.1 | 2.11.3 | 100 |
| | E | 28493 | 2.10 2.10.1 | | |
| | | GHSA-g3rq- | 2.10.2 2.10.3 | | |
| | | g295-4j3m | 2.1.1 2.11.0 | | |
| | | PYSEC-2021-66 | 2.11.1 2.11.2 | | |
| | | SNYK-PYTHON-J | 2.2 2.2.1 2.3 | | |
| | | INJA2-1012994 | 2.3.1 2.4 2.4.1 | | |
| | | | 2.5 2.5.1 2.5.2 | | |
| | | | 2.5.3 2.5.4 | | |
| | | | 2.5.5 2.6 2.7 | | |
| | | | 2.7.1 2.7.2 | | |
| | | | 2.7.3 2.8 2.8.1 | | |
| | | | 2.9 2.9.1 2.9.2 | | |
| | | | 2.9.3 2.9.4 | | |
| | | | 2.9.5 2.9.6 | | |
+-----------------+---------------+---------------+--------------------+--------------------+--------+
| | | | vers:pypi/>=2.0rc1 | vers:pypi/2.11.3 | |
| | | | |<=2.11.2 | | |
+-----------------+---------------+---------------+--------------------+--------------------+--------+
| CVE-2020-28493 | SAFETYDB | CVE-2020- | <2.11.3 | | 67 |
| | | 28493 | | | |
| | | pyup.io-39525 | | | |
+-----------------+---------------+---------------+--------------------+--------------------+--------+
| | | | vers:pypi/>=2.0rc1 | [] | |
| | | | |<=2.11.2 | | |
+-----------------+---------------+---------------+--------------------+--------------------+--------+
| CVE-2020-28493 | GITHUB | CVE-2020- | < 2.11.3 | 2.11.3 | 100 |
| | | 28493 | | | |
| | | GHSA-g3rq- | | | |
| | | g295-4j3m | | | |
+-----------------+---------------+---------------+--------------------+--------------------+--------+
| | | | vers:pypi/>=2.0rc1 | vers:pypi/2.11.3 | |
| | | | |<=2.11.2 | | |
+-----------------+---------------+---------------+--------------------+--------------------+--------+
| CVE-2019-10906 | VULNERABLECOD | CVE-2019- | 2.0 2.0rc1 2.1 | 2.10.1 | 100 |
| | E | 10906 | 2.10 2.1.1 2.2 | | |
| | | GHSA-462w- | 2.2.1 2.3 2.3.1 | | |
| | | v97r-4m45 | 2.4 2.4.1 2.5 | | |
| | | PYSEC-2019- | 2.5.1 2.5.2 | | |
| | | 217 | 2.5.3 2.5.4 | | |
| | | | 2.5.5 2.6 2.7 | | |
| | | | 2.7.1 2.7.2 | | |
| | | | 2.7.3 2.8 2.8.1 | | |
| | | | 2.9 2.9.1 2.9.2 | | |
| | | | 2.9.3 2.9.4 | | |
| | | | 2.9.5 2.9.6 | | |
+-----------------+---------------+---------------+--------------------+--------------------+--------+
| | | | vers:pypi/>=2.0rc1 | vers:pypi/2.10.1 | |
| | | | |<=2.10 | | |
+-----------------+---------------+---------------+--------------------+--------------------+--------+
| CVE-2019-10906 | SAFETYDB | CVE-2019- | >=0,<2.10.1 | | 67 |
| | | 10906 | | | |
| | | pyup.io-54679 | | | |
+-----------------+---------------+---------------+--------------------+--------------------+--------+
| | | | vers:pypi/>=2.0rc1 | [] | |
| | | | |<=2.10 | | |
+-----------------+---------------+---------------+--------------------+--------------------+--------+
| CVE-2019-10906 | GITHUB | CVE-2019- | < 2.10.1 | 2.10.1 | 100 |
| | | 10906 | | | |
| | | GHSA-462w- | | | |
| | | v97r-4m45 | | | |
+-----------------+---------------+---------------+--------------------+--------------------+--------+
| | | | vers:pypi/>=2.0rc1 | vers:pypi/2.10.1 | |
| | | | |<=2.10 | | |
+-----------------+---------------+---------------+--------------------+--------------------+--------+
| CVE-2016-10745 | VULNERABLECOD | CVE-2016- | 2.0 2.0rc1 2.1 | 2.8.1 | 100 |
| | E | 10745 | 2.1.1 2.2 2.2.1 | | |
| | | GHSA- | 2.3 2.3.1 2.4 | | |
| | | hj2j-77xm- | 2.4.1 2.5 2.5.1 | | |
| | | mc5v | 2.5.2 2.5.3 | | |
| | | PYSEC-2019- | 2.5.4 2.5.5 2.6 | | |
| | | 220 | 2.7 2.7.1 2.7.2 | | |
| | | | 2.7.3 2.8 | | |
+-----------------+---------------+---------------+--------------------+--------------------+--------+
| | | | vers:pypi/>=2.0rc1 | vers:pypi/2.8.1 | |
| | | | |<=2.8 | | |
+-----------------+---------------+---------------+--------------------+--------------------+--------+
| CVE-2016-10745 | SAFETYDB | CVE-2016- | <2.8.1 | | 67 |
| | | 10745 | | | |
| | | pyup.io-47572 | | | |
+-----------------+---------------+---------------+--------------------+--------------------+--------+
| | | | vers:pypi/>=2.0rc1 | [] | |
| | | | |<=2.8 | | |
+-----------------+---------------+---------------+--------------------+--------------------+--------+
| CVE-2016-10745 | GITHUB | CVE-2016- | < 2.8.1 | 2.8.1 | 100 |
| | | 10745 | | | |
| | | GHSA- | | | |
| | | hj2j-77xm- | | | |
| | | mc5v | | | |
+-----------------+---------------+---------------+--------------------+--------------------+--------+
| | | | vers:pypi/>=2.0rc1 | vers:pypi/2.8.1 | |
| | | | |<=2.8 | | |
+-----------------+---------------+---------------+--------------------+--------------------+--------+
| CVE-2014-1402 | VULNERABLECOD | CVE-2014-1402 | 2.0 2.0rc1 2.1 | 2.7.2 | 100 |
| | E | GHSA-8r7q- | 2.1.1 2.2 2.2.1 | | |
| | | cvjq-x353 | 2.3 2.3.1 2.4 | | |
| | | PYSEC-2014-8 | 2.4.1 2.5 2.5.1 | | |
| | | | 2.5.2 2.5.3 | | |
| | | | 2.5.4 2.5.5 2.6 | | |
| | | | 2.7 2.7.1 | | |
+-----------------+---------------+---------------+--------------------+--------------------+--------+
| | | | vers:pypi/>=2.0rc1 | vers:pypi/2.7.2 | |
| | | | |<=2.7.1 | | |
+-----------------+---------------+---------------+--------------------+--------------------+--------+
| CVE-2014-1402 | SAFETYDB | CVE-2014-1402 | <2.7.2 | | 67 |
| | | pyup.io-25866 | | | |
+-----------------+---------------+---------------+--------------------+--------------------+--------+
| | | | vers:pypi/>=2.0rc1 | [] | |
| | | | |<=2.7.1 | | |
+-----------------+---------------+---------------+--------------------+--------------------+--------+
| CVE-2014-1402 | GITHUB | CVE-2014-1402 | < 2.7.2 | 2.7.2 | 100 |
| | | GHSA-8r7q- | | | |
| | | cvjq-x353 | | | |
+-----------------+---------------+---------------+--------------------+--------------------+--------+
| | | | vers:pypi/>=2.0rc1 | vers:pypi/2.7.2 | |
| | | | |<=2.7.1 | | |
+-----------------+---------------+---------------+--------------------+--------------------+--------+
| CVE-2014-0012 | VULNERABLECOD | CVE-2014-0012 | 2.0 2.0rc1 2.1 | 2.7.3 | 100 |
| | E | GHSA-fqh9- | 2.1.1 2.2 2.2.1 | | |
| | | 2qgg-h84h | 2.3 2.3.1 2.4 | | |
| | | PYSEC-2014-82 | 2.4.1 2.5 2.5.1 | | |
| | | | 2.5.2 2.5.3 | | |
| | | | 2.5.4 2.5.5 2.6 | | |
| | | | 2.7 2.7.1 2.7.2 | | |
+-----------------+---------------+---------------+--------------------+--------------------+--------+
| | | | vers:pypi/>=2.0rc1 | vers:pypi/2.7.3 | |
| | | | |<=2.7.2 | | |
+-----------------+---------------+---------------+--------------------+--------------------+--------+
| CVE-2014-0012 | SAFETYDB | CVE-2014-0012 | >=0,<2.7.3 | | 100 |
| | | pyup.io-54674 | | | |
+-----------------+---------------+---------------+--------------------+--------------------+--------+
| | | | vers:pypi/>=2.0rc1 | [] | |
| | | | |<=2.7.2 | | |
+-----------------+---------------+---------------+--------------------+--------------------+--------+
| CVE-2014-0012 | GITHUB | CVE-2014-0012 | < 2.7.2 | 2.7.2 | 0 |
| | | GHSA-fqh9- | | | |
| | | 2qgg-h84h | | | |
+-----------------+---------------+---------------+--------------------+--------------------+--------+
| | | | vers:pypi/>=2.0rc1 | vers:pypi/2.7.2 | |
| | | | |<=2.7.1 | | |
+-----------------+---------------+---------------+--------------------+--------------------+--------+
| CVE-2024-34064 | SAFETYDB | CVE-2024- | <3.1.4 | | 100 |
| | | 34064 | | | |
| | | pyup.io-71591 | | | |
+-----------------+---------------+---------------+--------------------+--------------------+--------+
| | | | vers:pypi/>=2.0rc1 | [] | |
| | | | |<=3.1.3 | | |
+-----------------+---------------+---------------+--------------------+--------------------+--------+
| CVE-2024-34064 | GITHUB | CVE-2024- | < 3.1.4 | 3.1.4 | 100 |
| | | 34064 | | | |
| | | GHSA-h75v- | | | |
| | | 3vvj-5mfj | | | |
+-----------------+---------------+---------------+--------------------+--------------------+--------+
| | | | vers:pypi/>=2.0rc1 | vers:pypi/3.1.4 | |
| | | | |<=3.1.3 | | |
+-----------------+---------------+---------------+--------------------+--------------------+--------+
| CVE-2019-8341 | SAFETYDB | CVE-2019-8341 | >=0 | | NA |
| | | pyup.io-70612 | | | |
+-----------------+---------------+---------------+--------------------+--------------------+--------+
| | | | vers:pypi/>=2.0rc1 | [] | |
| | | | |<=3.1.4 | | |
+-----------------+---------------+---------------+--------------------+--------------------+--------+ |
keshav-space
force-pushed
the
advisory_compare
branch
from
March 17, 2023 15:51
18ca142 to
947fceb
Compare
keshav-space
force-pushed
the
advisory_compare
branch
from
April 3, 2023 12:10
947fceb to
170c21e
Compare
keshav-space
marked this pull request as draft
November 19, 2023 18:01
Member
|
@keshav-space we should merge this soon enough IMHO :) |
Member
Author
ack |
Member
|
@keshav-space can you help merge the latest main and then merge? |
Contributor
|
@keshav-space if this PR is ready to be merged, feel free to merge. If it's WIP feel free to close this and open it once it's ready |
Signed-off-by: Keshav Priyadarshi <git@keshav.space>
Signed-off-by: Keshav Priyadarshi <git@keshav.space>
Signed-off-by: Keshav Priyadarshi <git@keshav.space>
Signed-off-by: Keshav Priyadarshi <git@keshav.space>
- Add debug flag --vers to display equivalent normalized versions for corresponding native ranges. - Add debug flag --no-compare to run the CLI without comparison. - Auto-adjust text table width based on the terminal width. Signed-off-by: Keshav Priyadarshi <git@keshav.space>
Signed-off-by: Keshav Priyadarshi <git@keshav.space>
Signed-off-by: Keshav Priyadarshi <git@keshav.space>
Signed-off-by: Keshav Priyadarshi <git@keshav.space>
Signed-off-by: Keshav Priyadarshi <git@keshav.space>
keshav-space
force-pushed
the
advisory_compare
branch
from
July 26, 2024 12:44
170c21e to
96299a4
Compare
Signed-off-by: Keshav Priyadarshi <git@keshav.space>
keshav-space
marked this pull request as ready for review
July 26, 2024 14:56
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Add debug flag --vers to display equivalent normalized versions for corresponding native ranges.
Add debug flag --no-compare to run the CLI without comparison.
Dynamically adjust text table width based on the terminal width.
Minor bug fixes and improvements in existing DataSources.
Bump univers to v30.12.0
Depends on: Support Normalization of VersionRange univers#108
Fixes Version range normalization for range comparison across different DataSources in VulnTotal #1136
Fixes Cluster analysis of advisory fetched from different DataSource in VulnTotal #822
Note: Workflows is failing as aboutcode-org/univers#108 is not yet merged in univers