Skip to content

fedcode-next: Code pipeline and models to continuously automatically collect fix commits #1721

Description

@pombredanne

We should have a code pipeline and models to continuously automatically collect commits and patches that introduce or fix a vulnerability to support reachability analysis. There is already some base that analyses references. Here we need to dig deeper and scout the commits logs, changelogs and issues logs to discover and bisect if needed to find the subset of the code changes that we care for.

Today we can detect fix commits based some explicit references to commits, these are not always correct. We could validate the fix commits we have already

We have multiples issues that need to be triaged and "defragmented".
We need one issue with only the usable research/projects to:

Activity

  1. ArkaprabhaChakraborty commented on Jan 20, 2025

    @ArkaprabhaChakraborty

    Hi @pombredanne! as discussed over the call I want to work on this.

  2. ArkaprabhaChakraborty commented on Jan 20, 2025

    @ArkaprabhaChakraborty

    but before diving into this I want to contribute to a quickie good first issue on the similar track.

  3. self-assigned this
    on Oct 6, 2025
  4. self-assigned this
    on Oct 7, 2025
  5. TG1999 commented on Oct 11, 2025

    @TG1999
    Contributor

    IMO we should treat fix commit data as advisory, but special advisory. As brought up by @keshav-space we can accomodate the changes in impacted package data model as well. Thanks!

  6. ziadhany commented on Oct 11, 2025

    @ziadhany
    Collaborator

    I agree with that we should treat fix commits as advisory and may be avoid creating Codefixv2 entries directly relying on the CollectFixCommitsPipeline to create a Codefixv2 and associate them with the impacted package data model.

    but this will limit our abilities to detect/store fix commit that is no related to any aliases as some developer just fix a vulnerabilities without creating a CVE but I think this is out of scope for now, especially since many of these cases are false positives.

    IMO we should start with simple pipeline that parse git logs from key repositories linux / django
    using regular expression searching for CVE-xx, GHSA-xx or XSA-xx and store them as advisory with some references

    For example:

    this will generate a really interested fix commits we are really missing vulnerablecode

  7. pombredanne commented on Oct 15, 2025

    @pombredanne
    MemberAuthor

    This PR is ready for review:

  8. ziadhany commented on May 14, 2026

    @ziadhany
    Collaborator

    These are also some PRs we need to merge:

    More data collection for code commits:

    Collect GitHub PoCs:

  9. ziadhany commented on May 15, 2026

    @ziadhany
    Collaborator

    This is done now. This will continuously and automatically collect fix commits to track introduction or fix of a vulnerability.

    see:

    And the four main tracking issues have also been completed:

  10. moved this from Done to Reviewed in 00-AboutCodePlanneron May 28, 2026
  11. moved this from Reviewed to Done in 00-AboutCodePlanneron Jun 5, 2026
  12. moved this from Done to Reviewed in 00-AboutCodePlanneron Jul 2, 2026
  13. moved this from Reviewed to Validated in 00-AboutCodePlanneron Aug 5, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

No labels
No labels

Type

No type

Projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions