VEX: add rh vex beta feed testing and parsing mitigations - #1871
Merged
Conversation
crozzy
force-pushed
the
vex-beta-testing
branch
7 times, most recently
from
May 14, 2026 23:08
a1a972f to
d8bef0e
Compare
crozzy
force-pushed
the
vex-beta-testing
branch
3 times, most recently
from
May 26, 2026 21:53
2e08e80 to
55ff5bc
Compare
crozzy
force-pushed
the
vex-beta-testing
branch
2 times, most recently
from
August 10, 2026 21:09
15b156e to
cc79a27
Compare
crozzy
force-pushed
the
vex-beta-testing
branch
3 times, most recently
from
August 10, 2026 22:29
61b93c3 to
44cb203
Compare
crozzy
marked this pull request as ready for review
August 10, 2026 22:30
crozzy
force-pushed
the
vex-beta-testing
branch
2 times, most recently
from
August 11, 2026 17:42
61ae779 to
2d3c93e
Compare
Contributor
Author
|
I moved the VEX integration tests to |
hdonnay
requested changes
Aug 19, 2026
crozzy
force-pushed
the
vex-beta-testing
branch
2 times, most recently
from
August 19, 2026 16:05
debb1bc to
b5fca96
Compare
crozzy
commented
Aug 19, 2026
hdonnay
requested changes
Aug 19, 2026
crozzy
force-pushed
the
vex-beta-testing
branch
from
August 19, 2026 16:14
b5fca96 to
e05dc91
Compare
hdonnay
previously approved these changes
Aug 19, 2026
crozzy
force-pushed
the
vex-beta-testing
branch
3 times, most recently
from
August 19, 2026 18:30
6e7acda to
a00e372
Compare
Add WithBaseURL() ParserOption and use it to create a self URL when the VEX document doesn't contain csaf.CSAF.Document.References['self']. Signed-off-by: crozzy <joseph.crosland@gmail.com>
Ignore src/nosrc when building vulnerabilities so they do not overwrite empty archs from binary entries that share an arch-agnostic status key. Signed-off-by: crozzy <joseph.crosland@gmail.com>
The new Red Hat VEX feed is generally available and these tests help verify some specific regressions are fixed. Signed-off-by: crozzy <joseph.crosland@gmail.com>
crozzy
force-pushed
the
vex-beta-testing
branch
from
August 19, 2026 18:37
a00e372 to
592dc74
Compare
Contributor
Author
|
@hdonnay sorry, turns out the rebase was a little more involved due to me circling the same files for ~ a month so I think I need another review |
hdonnay
approved these changes
Aug 19, 2026
Contributor
Author
|
/fast-forward |
|
Triggered from #1871 (comment) by @crozzy. Trying to fast forward Target branch ( commit 6b23c3f53e46ab997e974eb54cc8a1d863f45de2 (HEAD -> main, origin/main)
Author: Hank Donnay <hdonnay@redhat.com>
Date: Tue Aug 11 12:16:39 2026 -0500
postgres: add XXH64 vulnerability hash for comparison
Signed-off-by: Hank Donnay <hdonnay@redhat.com>
Change-Id: I3f9b6a1675678dca3e669dced0007a8a6a6a6964Pull request ( commit 592dc742dc85bf6a60b4a01db976d9fc514891d4 (pull_request/vex-beta-testing)
Author: Joseph Crosland <jcroslan@redhat.com>
Date: Wed Apr 29 14:14:48 2026 -0700
test: add red hat vex beta testing
The new Red Hat VEX feed is generally available and these tests help
verify some specific regressions are fixed.
Signed-off-by: crozzy <joseph.crosland@gmail.com>Fast forwarding $ git push origin 592dc742dc85bf6a60b4a01db976d9fc514891d4:main
To https://github.com/quay/claircore.git
! [remote rejected] 592dc742dc85bf6a60b4a01db976d9fc514891d4 -> main (refusing to allow a GitHub App to create or update workflow `.github/workflows/updater-check.yml` without `workflows` permission)
error: failed to push some refs to 'https://github.com/quay/claircore.git' |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
In order to ingest the new Red Hat VEX feed we need to update a couple of things:
fixedandknown_not_affectedarrays, the system is always assuming binaries here and we're always matching to binary RPMs from the layer filesystem