Skip to content

recognize github repositories in advisories #10118

Description

@edwintorok

Related to #10117.
The advisory GHSA-x37h-cx7x-wm76 is linked to a CVE and OSV advisory, but not to any github repository.
The OSV data contains the repository, see https://github.com/ocaml/security-advisories/blob/generated-osv/2026/OSEC-2026-15.json

       {
          "type": "GIT",
          "repo": "https://github.com/mirage/mirage-crypto.git",
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "1f0bf67044e67cf6e46911fcd77a0ff706b6c3e7"
            }
          ]
        }

It would be nice if the advisory import system could recognize github URLs from CVE or OSV metadata, and link them to the appropriate repository.
This change would benefit any ecosystem that uses OSV, but is not yet a recognized ecosystem by Github, without having to add special supported for each ecosystem in turn: you'd only need to implement the generic handling to recognize the repository from OSV advisories once, and it'd work for all advisories on OSV.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions