Repository navigation
fedcode-next: Code pipeline and models to continuously automatically collect fix commits #1721
Description
Activity
Hi @pombredanne! as discussed over the call I want to work on this.
but before diving into this I want to contribute to a quickie good first issue on the similar track.
- added sub-issues
on Jul 18, 2025 IMO we should treat fix commit data as advisory, but special advisory. As brought up by @keshav-space we can accomodate the changes in impacted package data model as well. Thanks!
Reacted by ziadhanyI agree with that we should treat fix commits as advisory and may be avoid creating Codefixv2 entries directly relying on the CollectFixCommitsPipeline to create a
Codefixv2and associate them with the impacted package data model.but this will limit our abilities to detect/store fix commit that is no related to any
aliasesas some developer just fix a vulnerabilities without creating a CVE but I think this is out of scope for now, especially since many of these cases are false positives.IMO we should start with simple pipeline that parse git logs from key repositories
linux/django
using regular expression searching for CVE-xx, GHSA-xx or XSA-xx and store them as advisory with some referencesFor example:
this will generate a really interested fix commits we are really missing vulnerablecode
This PR is ready for review:
- Add support for parsing Git commit messages #1992 ... it parse fix commits from the Git commits
To close this issue, we need to merge these PRs in sequence:
- Add support for collecting fix commits and (PRs and issues) aboutcode-data/vulnerablecode-vcs-collector#1
- Add the VCS Collector importer #2254
- Add support for Reference Fix Commits improver #2163
- Add API/ UI support for Patch/PackageCommitPatch #2179
- Improver to collect patch texts wherever patch text is missing #2184
These are also some PRs we need to merge:
More data collection for code commits:
Collect GitHub PoCs:
This is done now. This will continuously and automatically collect fix commits to track introduction or fix of a vulnerability.
see:
- OSV data: Fix OSV to handle affected_packages correctly & add support to collect commits #2080
- project-kb: Migrate Importer to Advisory v2 & Collect Existing Fix Commits for Project KB #1987
- linux_kernel_cves: Collect existing fix commits for Linux Kernel #1989
- GNU Libc fix commits: Add support for glib importer #2118
- Android fixes from: Add support for introduced and fixed commits in AdvisoryData #2017
- Collect GitHub PoCs: Add GitHub PoC collector #2024
- Collect Issues/PRs/commit logs:
And the four main tracking issues have also been completed:
- Collect fix commits from pre-existing datasets fedcode-next: Collect fix commits from pre-existing datasets #2003
- Extract fix commits from the commit logs in search for CVE-related commit messages fedcode-next: Extract fix commits from the commit logs in search for CVE-related commit messages #2000
- Extract fix commits from pull requests and issues body or comments in search for CVE-related messages fedcode-next: Extract fix commits from pull requests and issues body or comments in search for CVE-related messages #2002
- Extract fix commits from the change logs in search for CVE-related change entries fedcode-next: Extract fix commits from the change logs in search for CVE-related change entries #2001
Metadata
Metadata
Assignees
Labels
Type
Projects
- StatusShow more project fieldsValidated
We should have a code pipeline and models to continuously automatically collect commits and patches that introduce or fix a vulnerability to support reachability analysis. There is already some base that analyses references. Here we need to dig deeper and scout the commits logs, changelogs and issues logs to discover and bisect if needed to find the subset of the code changes that we care for.
Today we can detect fix commits based some explicit references to commits, these are not always correct. We could validate the fix commits we have already
We have multiples issues that need to be triaged and "defragmented".
We need one issue with only the usable research/projects to: