diff --git a/tasks/script-to-extract-fixed-cves/component-mapping.md b/tasks/script-to-extract-fixed-cves/component-mapping.md new file mode 100644 index 0000000..e817beb --- /dev/null +++ b/tasks/script-to-extract-fixed-cves/component-mapping.md @@ -0,0 +1,18 @@ +logging-view-plugin 6.0 release-6.0 release-coo-ocp-4.12 GA ui-logging-pf4 4.12, 4.13, 4.14 COO 1.5.0 logging-console-plugin-pf4 +logging-view-plugin 6.1 release-6.1 release-coo-ocp-4.15 GA ui-logging-pf5 4.15, 4.16, 4.17, 4,18, 4.19, 4.20, 4.21 COO +1.5.0 logging-console-plugin-pf5 logging-view-plugin 6.2 release-6.2 release-coo-ocp-4.22 GA ui-logging 4.22 COO 1.5.0 logging-console-plugin +console-dashboards-plugin 0.4 release-0.4 release-coo-ocp-4.12 DP ui-dashboards 4.12, 4.13, 4.14, 4.15, 4.16, 4.17, 4.18, 4.19, 4.20, 4.21, 4.22 COO +1.5.0 dashboards-console-plugin distributed-tracing-console-plugin 0.3 release-0.3 release-coo-ocp-4.12 TP ui-distributed-tracing-pf4 4.12, 4.13, +4.14 COO 1.5.0 distributed-tracing-console-plugin-pf4 +distributed-tracing-console-plugin 0.4 release-0.4 release-coo-ocp-4.15 TP ui-distributed-tracing-pf5 4.15, 4.16, 4.17, 4.18 COO +1.5.0 distributed-tracing-console-plugin-pf5 +distributed-tracing-console-plugin 1.0 release-1.0 release-coo-ocp-4.19 GA ui-distributed-tracing-pf6 4.19, 4.20, 4.21 COO +1.5.0 distributed-tracing-console-plugin-pf6 +distributed-tracing-console-plugin 1.1 release-1.1 release-coo-ocp-4.22 GA ui-distributed-tracing 4.22 COO 1.5.0 distributed-tracing-console-plugin +troubleshooting-panel-console-plugin 0.4 release-0.4 release-coo-ocp-4.19 GA ui-troubleshooting-panel-pf6 4.19, 4.20, 4.21 COO +1.5.0 troubleshooting-panel-console-plugin-pf6 +troubleshooting-panel-console-plugin 1.0 release-1.0 release-coo-ocp-4.22 GA ui-troubleshooting-panel 4.22 COO +1.5.0 troubleshooting-panel-console-plugin monitoring-console-plugin 0.4 release-coo-0.4 release-coo-ocp-4.15 DP ui-monitoring-pf5 4.15, 4.16, 4.17, +4.18 COO 1.5.0 monitoring-console-plugin-pf5 monitoring-console-plugin 0.5 release-coo-0.5 release-coo-ocp-4.19 GA ui-monitoring-pf6 4.19, 4.20, +4.21 COO 1.5.0 monitoring-console-plugin-pf6 monitoring-console-plugin 1.0 release-coo-1.0 release-coo-ocp-4.22 GA ui-monitoring 4.22 COO +1.5.0 monitoring-console-plugin diff --git a/tasks/script-to-extract-fixed-cves/config.yaml b/tasks/script-to-extract-fixed-cves/config.yaml new file mode 100644 index 0000000..332f316 --- /dev/null +++ b/tasks/script-to-extract-fixed-cves/config.yaml @@ -0,0 +1,67 @@ +default_rollback: 3 + +entries: + - project: perses-operator + branch: release-coo-1.5 + component: perses-operator-1-5 + rollback: 3 + + - project: monitoring-plugin + branch: release-coo-ocp-4.15 + component: monitoring-console-plugin-pf5-1-5 + rollback: 2 + + - project: monitoring-plugin + branch: release-coo-ocp-4.19 + component: monitoring-console-plugin-pf6-1-5 + rollback: 2 + + - project: monitoring-plugin + branch: release-coo-ocp-4.22 + component: monitoring-console-plugin-1-5 + rollback: 2 + + - project: logging-view-plugin + branch: release-coo-ocp-4.12 + component: logging-console-plugin-pf4-1-5 + rollback: 2 + + - project: logging-view-plugin + branch: release-coo-ocp-4.15 + component: logging-console-plugin-pf5-1-5 + rollback: 2 + + - project: logging-view-plugin + branch: release-coo-ocp-4.22 + component: logging-console-plugin-1-5 + rollback: 2 + + - project: distributed-tracing-plugin + branch: release-coo-ocp-4.12 + component: distributed-tracing-console-plugin-pf4-1-5 + rollback: 2 + + - project: distributed-tracing-plugin + branch: release-coo-ocp-4.15 + component: distributed-tracing-console-plugin-pf5-1-5 + rollback: 2 + + - project: distributed-tracing-plugin + branch: release-coo-ocp-4.19 + component: distributed-tracing-console-plugin-pf6-1-5 + rollback: 2 + + - project: distributed-tracing-plugin + branch: release-coo-ocp-4.22 + component: distributed-tracing-console-plugin-1-5 + rollback: 2 + + - project: troubleshooting-panel-plugin + branch: release-coo-ocp-4.19 + component: troubleshooting-panel-console-plugin-pf6-1-5 + rollback: 2 + + - project: troubleshooting-panel-plugin + branch: release-coo-ocp-4.22 + component: troubleshooting-panel-console-plugin-1-5 + rollback: 2 diff --git a/tasks/script-to-extract-fixed-cves/cve-matrix-output.csv b/tasks/script-to-extract-fixed-cves/cve-matrix-output.csv new file mode 100644 index 0000000..5523d29 --- /dev/null +++ b/tasks/script-to-extract-fixed-cves/cve-matrix-output.csv @@ -0,0 +1,27 @@ +Component,CVE-2026-27137,CVE-2026-42508,CVE-2026-40179,CVE-2026-39883,CVE-2026-39828,CVE-2026-39832,CVE-2026-39821,CVE-2026-44973,CVE-2026-39831,CVE-2026-25681,CVE-2026-27136,CVE-2026-42502,CVE-2026-39829,CVE-2026-46598,CVE-2026-46597,CVE-2026-39835,CVE-2026-39830,CVE-2026-33814,CVE-2026-39882,CVE-2026-29181,CVE-2026-42151,CVE-2026-42154,CVE-2026-44740,CVE-2026-41567,CVE-2026-46595,CVE-2020-7753,CVE-2021-33623,CVE-2024-4068,CVE-2024-45338,CVE-2024-52011,CVE-2025-22868,CVE-2025-22870,CVE-2025-22872,CVE-2025-47911,CVE-2025-58190,CVE-2026-12143,CVE-2026-12151,CVE-2026-1526,CVE-2026-1528,CVE-2026-2229,CVE-2026-25680,CVE-2026-29063,CVE-2026-32141,CVE-2026-33228,CVE-2026-33671,CVE-2026-33891,CVE-2026-33894,CVE-2026-33895,CVE-2026-33896,CVE-2026-33937,CVE-2026-33938,CVE-2026-33939,CVE-2026-33940,CVE-2026-33941,CVE-2026-39824,CVE-2026-42506,CVE-2026-44705,CVE-2026-44728,CVE-2026-4800,CVE-2026-4867,CVE-2026-48779,CVE-2026-48801,CVE-2026-6321,CVE-2026-6322,CVE-2026-6734,CVE-2026-9277,CVE-2026-9697 +Solution,,,,,,,Updated golang.org/x/net in go.mod,,,Updated golang.org/x/net in go.mod,Updated golang.org/x/net in go.mod,Updated golang.org/x/net in go.mod,,,,,,Updated golang.org/x/net in go.mod,,,,,,,,Updated trim in package.json,Updated trim-newlines in package.json,Updated braces in package.json,Updated golang.org/x/net in go.mod,Updated launch-editor in package.json,Updated golang.org/x/oauth2 in go.mod,Updated golang.org/x/net in go.mod,Updated golang.org/x/net in go.mod,Updated golang.org/x/net in go.mod,Updated golang.org/x/net in go.mod,Updated form-data in package.json,Updated undici in package.json,Updated undici in package.json,Updated undici in package.json,Updated undici in package.json,Updated golang.org/x/net in go.mod,Updated immutable in package.json,Updated flatted in package.json,Updated flatted in package.json,Updated picomatch in package.json,Updated node-forge in package.json,Updated node-forge in package.json,Updated node-forge in package.json,Updated node-forge in package.json,Updated handlebars in package.json,Updated handlebars in package.json,Updated handlebars in package.json,Updated handlebars in package.json,Updated handlebars in package.json,Updated golang.org/x/sys in go.mod,Updated golang.org/x/net in go.mod,Updated tmp in package.json,Updated @babel/plugin-transform-modules-systemjs in package.json,Updated lodash in package.json,Updated path-to-regexp in package.json,Updated ws in package.json,Updated linkify-it in package.json,Updated fast-uri in package.json,Updated fast-uri in package.json,Updated undici in package.json,Updated shell-quote in package.json,Updated undici in package.json +alertmanager-1-5,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,, +cluster-health-analyzer-1-5,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,, +cluster-observability-operator-1-5,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,, +cluster-observability-operator-bundle-1-5,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,, +dashboards-console-plugin-1-5,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,, +distributed-tracing-console-plugin-1-5,,,,,,,X,,,X,X,X,,,,,,X,,,,,,,,,,,,,,,,,,X,X,,,,X,,,,,,,,,,,,,,X,X,X,X,,,X,,X,X,X,X,X +distributed-tracing-console-plugin-pf4-1-5,,,,,,,X,,,X,X,X,,,,,,X,,,,,,,,X,X,X,,,,X,X,X,X,X,X,,,,X,,,,,,,,,,,,,,X,X,X,X,,,X,,X,X,X,X,X +distributed-tracing-console-plugin-pf5-1-5,,,,,,,X,,,X,X,X,,,,,,X,,,,,,,,,,,,,,,,,,X,X,,,,X,,,,,,,,,,,,,,X,X,X,X,,,X,,X,X,X,X,X +distributed-tracing-console-plugin-pf6-1-5,,,,,,,X,,,X,X,X,,,,,,X,,,,,,,,,,,,,,,,,,X,X,,,,X,,,,,,,,,,,,,,X,X,X,X,,,X,,X,X,X,X,X +korrel8r-1-5,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,, +logging-console-plugin-1-5,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,X,X,,,,,,,,,,,,,,,,,,,,X,X,,,X,,X,X,X,X,X +logging-console-plugin-pf4-1-5,,,,,,,X,,,X,X,X,,,,,,X,,,,,,,,,,,X,X,X,X,X,X,X,X,X,X,X,X,X,X,X,X,X,X,X,X,X,X,X,X,X,X,X,X,X,X,X,X,X,,X,X,,X, +logging-console-plugin-pf5-1-5,,,,,,,X,,,X,X,X,,,,,,X,,,,,,,,,,,,X,X,X,X,X,X,X,X,X,X,X,X,X,X,X,X,,,,,X,X,X,X,X,X,X,X,X,X,X,X,,X,X,,X, +monitoring-console-plugin-1-5,,,,,,,X,,,X,X,X,,,,,,X,,,,,,,,,,,,,X,X,X,X,X,X,X,,,,X,,,,,,,,,,,,,,X,X,X,X,,,X,X,X,X,X,X,X +monitoring-console-plugin-pf5-1-5,,,,,,,X,,,X,X,X,,,,,,X,,,,,,,,,,,,,X,X,X,X,X,X,X,,,,X,,,,,,,,,,,,,,X,X,X,,,,X,X,,,X,X,X +monitoring-console-plugin-pf6-1-5,,,,,,,X,,,X,X,X,,,,,,X,,,,,,,,,,,,,X,X,X,X,X,X,X,,,,X,,,,,,,,,,,,,,X,X,X,,,,X,X,,,X,X,X +obo-prometheus-operator-1-5,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,, +obo-prometheus-operator-admission-webhook-1-5,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,, +obo-prometheus-operator-prometheus-config-reloader-1-5,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,, +perses-1-5,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,, +perses-operator-1-5,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,, +prometheus-1-5,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,, +thanos-1-5,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,, +troubleshooting-panel-console-plugin-1-5,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,X,X,,,,,,,,,,,,,,,,,,,,X,X,,,X,,X,X,X,X,X +troubleshooting-panel-console-plugin-pf6-1-5,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,X,X,X,X,X,,X,X,X,X,,,,,X,X,X,X,X,,,X,X,X,X,X,,X,X,,X, diff --git a/tasks/script-to-extract-fixed-cves/cve-matrix-template.csv b/tasks/script-to-extract-fixed-cves/cve-matrix-template.csv new file mode 100644 index 0000000..b312d1e --- /dev/null +++ b/tasks/script-to-extract-fixed-cves/cve-matrix-template.csv @@ -0,0 +1,27 @@ +Component,CVE-2026-27137,CVE-2026-42508,CVE-2026-40179,CVE-2026-39883,CVE-2026-39828,CVE-2026-39832,CVE-2026-39821,CVE-2026-44973,CVE-2026-39831,CVE-2026-25681,CVE-2026-27136,CVE-2026-42502,CVE-2026-39829,CVE-2026-46598,CVE-2026-46597,CVE-2026-39835,CVE-2026-39830,CVE-2026-33814,CVE-2026-39882,CVE-2026-29181,CVE-2026-42151,CVE-2026-42154,CVE-2026-44740,CVE-2026-41567,CVE-2026-46595 +Solution,,,,,,,,,,,,,,,,,,,,,,,,, +alertmanager-1-5,,,,,,,,,,,,,,,,,,,,,,,,, +cluster-health-analyzer-1-5,,,,,,,,,,,,,,,,,,,,,,,,, +cluster-observability-operator-1-5,,,,,,,,,,,,,,,,,,,,,,,,, +cluster-observability-operator-bundle-1-5,,,,,,,,,,,,,,,,,,,,,,,,, +dashboards-console-plugin-1-5,,,,,,,,,,,,,,,,,,,,,,,,, +distributed-tracing-console-plugin-1-5,,,,,,,,,,,,,,,,,,,,,,,,, +distributed-tracing-console-plugin-pf4-1-5,,,,,,,,,,,,,,,,,,,,,,,,, +distributed-tracing-console-plugin-pf5-1-5,,,,,,,,,,,,,,,,,,,,,,,,, +distributed-tracing-console-plugin-pf6-1-5,,,,,,,,,,,,,,,,,,,,,,,,, +korrel8r-1-5,,,,,,,,,,,,,,,,,,,,,,,,, +logging-console-plugin-1-5,,,,,,,,,,,,,,,,,,,,,,,,, +logging-console-plugin-pf4-1-5,,,,,,,,,,,,,,,,,,,,,,,,, +logging-console-plugin-pf5-1-5,,,,,,,,,,,,,,,,,,,,,,,,, +monitoring-console-plugin-1-5,,,,,,,,,,,,,,,,,,,,,,,,, +monitoring-console-plugin-pf5-1-5,,,,,,,,,,,,,,,,,,,,,,,,, +monitoring-console-plugin-pf6-1-5,,,,,,,,,,,,,,,,,,,,,,,,, +obo-prometheus-operator-1-5,,,,,,,,,,,,,,,,,,,,,,,,, +obo-prometheus-operator-admission-webhook-1-5,,,,,,,,,,,,,,,,,,,,,,,,, +obo-prometheus-operator-prometheus-config-reloader-1-5,,,,,,,,,,,,,,,,,,,,,,,,, +perses-1-5,,,,,,,,,,,,,,,,,,,,,,,,, +perses-operator-1-5,,,,,,,,,,,,,,,,,,,,,,,,, +prometheus-1-5,,,,,,,,,,,,,,,,,,,,,,,,, +thanos-1-5,,,,,,,,,,,,,,,,,,,,,,,,, +troubleshooting-panel-console-plugin-1-5,,,,,,,,,,,,,,,,,,,,,,,,, +troubleshooting-panel-console-plugin-pf6-1-5,,,,,,,,,,,,,,,,,,,,,,,,, \ No newline at end of file diff --git a/tasks/script-to-extract-fixed-cves/execution.md b/tasks/script-to-extract-fixed-cves/execution.md new file mode 100644 index 0000000..7b2b246 --- /dev/null +++ b/tasks/script-to-extract-fixed-cves/execution.md @@ -0,0 +1,169 @@ +# Execution: Script to Extract Fixed CVEs + +> Results are annotated inline: `-- **value**` for discovered values, `-- **passes/FAILED**` for verification. + +## Phase 1: Core Script — Git Operations and Project Loop +Depends on: nothing | Parallel with: none | Type: implementation | Projects: ai-sdlc (tasks/) + +- [x] Create `tasks/script-to-extract-fixed-cves/extract-fixed-cves.sh` with project/branch config array +- [x] Add repo-name → local-dir mapping function (`get_local_dir`) +- [x] Add remote resolution function (`resolve_remote`) +- [x] Add git checkout/restore logic with original ref tracking -- **uses temp file instead of associative array for bash 3.x compat** +- [x] Fix `.git` check to use `-e` instead of `-d` for submodule gitlinks +- [x] Add `git checkout -- .` before branch switches to reset npm install side effects + +### Phase 1 Verification +- [x] `bash -n tasks/script-to-extract-fixed-cves/extract-fixed-cves.sh` — **passes** + +## Phase 2: NPM Audit Diff Logic +Depends on: Phase 1 | Parallel with: none (same file as Phase 3) | Type: implementation | Projects: ai-sdlc (tasks/) + +- [x] Add frontend directory detection function (`detect_frontend_dir`) +- [x] Add npm audit at HEAD and HEAD~N +- [x] Add `extract_npm_urls` function using jq to extract advisory URLs +- [x] Add `extract_npm_detail` function for report enrichment +- [x] Add diff logic: extract URLs from HEAD and HEAD~N, use `comm -23` to find fixed + +### Phase 2 Verification +- [x] jq expression correctly parses npm audit JSON format -- **passes, tested against distributed-tracing and troubleshooting-panel** + +## Phase 3: govulncheck Diff Logic +Depends on: Phase 1 | Parallel with: none (same file as Phase 2) | Type: implementation | Projects: ai-sdlc (tasks/) + +- [x] Add govulncheck run at HEAD and HEAD~N +- [x] Add `extract_go_ids` function using jq to extract OSV IDs from finding entries +- [x] Add `extract_go_detail` function for report enrichment (aliases, module, summary) +- [x] Add diff logic mirroring NPM approach + +### Phase 3 Verification +- [x] jq expression correctly parses govulncheck JSON format -- **passes, found 20-32 Go vulns fixed per branch** + +## Phase 4: Markdown Report Generation +Depends on: Phase 2, Phase 3 | Parallel with: none | Type: implementation | Projects: ai-sdlc (tasks/) + +- [x] Add report header generation with date +- [x] Add per-project/branch section generation (NPM + Go tables) +- [x] Add summary table generation at end with status column + +### Phase 4 Verification +- [x] Generated report.md is valid markdown with proper tables -- **passes** + +## Phase 5: Error Handling and Cleanup +Depends on: Phase 4 | Parallel with: none | Type: implementation | Projects: ai-sdlc (tasks/) + +- [x] Add cleanup trap (restore git state with `checkout -- .` + ref restore, remove temp files) +- [x] Add temp directory creation (`mktemp -d`) +- [x] Add tool availability checks (jq required, govulncheck optional, npm required) +- [x] Add dirty-worktree guard (refuse to run with uncommitted changes) +- [x] Add progress logging to stderr +- [x] Add skip for too-few-commits, missing remote, fetch failure + +### Phase 5 Verification +- [x] Script handles missing `govulncheck` gracefully -- **confirmed: HAS_GOVULNCHECK flag skips with warning** +- [x] Cleanup restores working trees correctly after normal completion -- **verified: projects back on main, clean** + +## End-to-End Verification +- [x] Run against `troubleshooting-panel:release-coo-ocp-4.19` — **20 Go vulns fixed detected** +- [x] Run against `distributed-tracing:release-coo-ocp-4.{12,15,19,22}` — **32, 28, 28, 0 Go vulns fixed** +- [x] Report contains proper markdown tables with CVE IDs, modules, summaries +- [x] Frontend detected in `web/` for UI plugins +- [x] Projects restored to main branch with clean working tree after script completes +- [x] Full parallel run of all 13 entries — **5 min, 362% CPU, all entries ok** + +--- + +## Phase 6: Parallel Execution by Project +> Added post-initial implementation to reduce wall-clock time from ~25 min to ~5 min. + +- [x] Extract entry processing into `process_entry` function with index-based output files +- [x] Add `process_project` function to run entries for the same project sequentially +- [x] Replace main for-loop with parallel dispatch: one background job per unique project +- [x] Write report sections to `$WORK_DIR/sections/NNNN.md` and summaries to `$WORK_DIR/summaries/NNNN.txt` for ordered assembly +- [x] Move refs tracking to per-project files (`$WORK_DIR/refs/${local_dir}.txt`) to avoid concurrent writes +- [x] Update cleanup to iterate over `$WORK_DIR/refs/*.txt` +- [x] Prefix stderr with `[$local_dir]` for readable interleaved output +- [x] Fix `pids[@]` unbound variable when filter matches no projects + +### Phase 6 Verification +- [x] Single-project test (`troubleshooting-panel`) — **passes, sequential within project** +- [x] Full 13-entry run — **5 min, 362% CPU, all entries ok, correct report order** +- [x] All projects restored to main with clean working trees + +## Phase 7: Fix NPM Audit JSON Corruption +> `npm install` stdout (e.g., `up to date, audited 1700 packages`) was written into the same file as `npm audit --json`, corrupting the JSON. jq silently returned nothing, so all npm reports were empty. + +- [x] Root cause: `(cd "$dir" && npm install 2>/dev/null && npm audit --json)` piped both commands' stdout into one file +- [x] Fix: redirect npm install stdout to `/dev/null` (`npm install >/dev/null 2>&1`) +- [x] Verified: monitoring-plugin 4.22 now reports 23 npm fixes (was 0) + +### Phase 7 Verification +- [x] monitoring-plugin: 20, 20, 23 npm fixes on 4.15, 4.19, 4.22 — **passes** + +## Phase 8: Remove `npm install` from HEAD Audit +> `npm audit` reads `package-lock.json` directly — `npm install` is unnecessary and can modify the lockfile, contaminating the HEAD vs HEAD~N comparison. + +- [x] Remove `npm install` from the HEAD audit pipeline (keep only `npm audit --json`) +- [x] Remove `--ignore-scripts --legacy-peer-deps` flags (user request) +- [x] Verified: `npm audit --json` produces identical results with and without `node_modules` (11 URLs both ways) + +### Phase 8 Verification +- [x] monitoring-plugin results consistent with manual `npm audit` — **passes** + +## Phase 9: Map GHSA Advisories to CVE IDs +> NPM audit reports advisory URLs (GHSA-xxxx) but errata/release notes need CVE IDs. GitHub Advisory API returns the mapping via `gh api /advisories/GHSA-xxxx`. + +- [x] Add `gh` CLI availability check (`HAS_GH` flag, graceful fallback to "N/A") +- [x] Add `fetch_cve_for_ghsa` function using `gh api` + `jq .cve_id` +- [x] Add CVE column to NPM report table: `| Advisory | CVE | Package | Severity | Title |` +- [x] Rate limit confirmed: 5000 req/hr, worst case ~520 calls — **no concern** + +### Phase 9 Verification +- [x] troubleshooting-panel 4.19: 48 npm advisories, all CVE-mapped — **passes** +- [x] Advisories without CVE show "N/A" (e.g., GHSA-442j, GHSA-7rx3) — **passes** + +## Phase 10: Add Commit Messages to Report +> Each report section now includes the commits being analyzed (HEAD~N..HEAD), giving context on what changes introduced the fixes. + +- [x] Capture `git log --oneline $remote/$branch~$ROLLBACK..$remote/$branch` before checkout +- [x] Add "Commits analyzed" subsection at top of each project/branch report section + +### Phase 10 Verification +- [x] perses-operator report shows 5 commit messages — **passes** + +## Phase 11: YAML Output with Konflux Component Mapping +> Errata tooling needs a YAML file mapping each fixed CVE to its Konflux component name. Component names come from a hardcoded mapping derived from `component-mapping.md`. + +- [x] Add `--yaml` flag parsing (coexists with optional filter argument) +- [x] Add `get_component` function: hardcoded `(project, branch) → component-name` mapping for all 13 entries +- [x] Cache CVE lookups in `$etmp/cve_cache.txt` during report generation to avoid duplicate API calls +- [x] Write per-entry YAML fragments to `$WORK_DIR/yaml/NNNN.yaml` +- [x] Assemble `report.yaml` from fragments in entry order after all jobs complete +- [x] Go CVEs: extract CVE-* aliases from `extract_go_detail` output +- [x] NPM CVEs: read from cache file (populated during report table generation) + +### Phase 11 Verification +- [x] `--yaml perses-operator`: 20 Go CVEs mapped to `perses-operator-1-5` — **passes** +- [x] YAML format matches spec: `cves:\n - key: CVE-xxx\n component: xxx` — **passes** +- [x] Without `--yaml`: no report.yaml generated — **passes** + +--- + +## Summary + +**Status:** Complete (all 11 phases done) + +### Script capabilities +- Parallel processing of 5 projects (entries for same project run sequentially) +- Diffs npm audit + govulncheck at HEAD vs HEAD~N to find fixed CVEs +- Markdown report with commit messages, NPM table (with CVE via GitHub API), Go table, and summary +- Optional `--yaml` output mapping CVEs to Konflux component names +- Graceful handling of missing tools, dirty worktrees, missing branches +- Cleanup trap restores all project working trees on exit + +### Usage +```bash +./extract-fixed-cves.sh # all projects, markdown only +./extract-fixed-cves.sh monitoring-plugin # filter by project name +./extract-fixed-cves.sh --yaml # all projects, markdown + YAML +./extract-fixed-cves.sh --yaml troubleshooting # filter + YAML +``` diff --git a/tasks/script-to-extract-fixed-cves/extract-fixed-cves.sh b/tasks/script-to-extract-fixed-cves/extract-fixed-cves.sh new file mode 100755 index 0000000..55f0cc8 --- /dev/null +++ b/tasks/script-to-extract-fixed-cves/extract-fixed-cves.sh @@ -0,0 +1,586 @@ +#!/usr/bin/env bash +set -euo pipefail + +SCRIPT_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)" +REPO_ROOT="$(cd "$SCRIPT_DIR/../.." && pwd)" +CONFIG_FILE="$SCRIPT_DIR/config.yaml" +REPORT="$SCRIPT_DIR/report.md" +WORK_DIR=$(mktemp -d) + +YAML_OUTPUT=true +FILTER="" +for arg in "$@"; do + case "$arg" in + --yaml) YAML_OUTPUT=true ;; + *) FILTER="$arg" ;; + esac +done + +mkdir -p "$WORK_DIR/sections" "$WORK_DIR/summaries" "$WORK_DIR/refs" "$WORK_DIR/yaml" + +HAS_GOVULNCHECK=true +if ! command -v govulncheck &>/dev/null; then + echo "[WARN] govulncheck not found — Go vulnerability checks will be skipped" >&2 + HAS_GOVULNCHECK=false +fi + +if ! command -v jq &>/dev/null; then + echo "[ERROR] jq is required. Install: brew install jq" >&2 + exit 1 +fi + +if ! command -v npm &>/dev/null; then + echo "[ERROR] npm is required." >&2 + exit 1 +fi + +if ! command -v yq &>/dev/null; then + echo "[ERROR] yq is required to parse config.yaml. Install: brew install yq" >&2 + exit 1 +fi + +HAS_GH=true +if ! command -v gh &>/dev/null; then + echo "[WARN] gh CLI not found — CVE mapping will be skipped" >&2 + HAS_GH=false +fi + +# ---- Load config ---- + +if [ ! -f "$CONFIG_FILE" ]; then + echo "[ERROR] Config file not found: $CONFIG_FILE" >&2 + exit 1 +fi + +DEFAULT_ROLLBACK=$(yq -r '.default_rollback // 3' "$CONFIG_FILE") + +ENTRIES=() +ENTRY_COMPONENTS=() +ENTRY_ROLLBACKS=() + +entry_count=$(yq '.entries | length' "$CONFIG_FILE") +for (( i=0; i&2 + +# ---- Pre-flight: validate all configured project directories ---- + +validation_errors=0 +seen_invalid_projects="" +for i in "${!ENTRIES[@]}"; do + entry="${ENTRIES[$i]}" + project="${entry%%:*}" + branch="${entry##*:}" + [ -n "$FILTER" ] && [[ "$project" != *"$FILTER"* ]] && continue + pdir="$REPO_ROOT/projects/$project" + if [ ! -e "$pdir/.git" ]; then + echo "[ERROR] [$project @ $branch] Project directory is not a git repo: $pdir" >&2 + # Print the fix hint once per unique project to avoid repetition + if [[ "$seen_invalid_projects" != *"|${project}|"* ]]; then + echo " Fix: git submodule update --init projects/$project" >&2 + seen_invalid_projects="${seen_invalid_projects}|${project}|" + fi + validation_errors=$((validation_errors + 1)) + fi +done +if [ "$validation_errors" -gt 0 ]; then + echo "[ERROR] $validation_errors entry/entries failed pre-flight validation — aborting." >&2 + exit 1 +fi + +# ---- Cleanup ---- + +cleanup() { + for refs_file in "$WORK_DIR"/refs/*.txt; do + [ -f "$refs_file" ] || continue + while IFS='|' read -r pdir ref; do + echo "[cleanup] Restoring $pdir" >&2 + git -C "$pdir" checkout -- . 2>/dev/null || true + git -C "$pdir" checkout "$ref" 2>/dev/null || true + done < "$refs_file" + done + rm -rf "$WORK_DIR" +} +trap cleanup EXIT + +# ---- Helper functions ---- + +resolve_remote() { + local pdir="$1" branch="$2" + # Try to find the remote by scanning already-fetched tracking branches. + # grep exits 1 when there is no match, so guard with || true to avoid a + # silent set -e exit before the caller can print a useful error message. + local remote + remote=$(git -C "$pdir" branch -r | grep -E "/${branch}$" | head -1 | sed 's/^[[:space:]]*//' | cut -d'/' -f1 || true) + if [ -z "$remote" ]; then + # Branch not fetched yet — fall back to the repo's first configured remote. + remote=$(git -C "$pdir" remote 2>/dev/null | head -1 || true) + fi + echo "$remote" +} + +detect_frontend_dir() { + local pdir="$1" + if [ -f "$pdir/web/package.json" ]; then + echo "$pdir/web" + elif [ -f "$pdir/package.json" ]; then + echo "$pdir" + else + echo "" + fi +} + +extract_npm_urls() { + local json_file="$1" + [ -s "$json_file" ] || return 0 + jq -r ' + .vulnerabilities // {} | to_entries[] | .value.via[]? | + select(type == "object") | .url // empty + ' "$json_file" 2>/dev/null | sort -u || true +} + +extract_npm_detail() { + local json_file="$1" url="$2" + [ -s "$json_file" ] || return 0 + jq -r --arg url "$url" ' + .vulnerabilities // {} | to_entries[] | .value.via[]? | + select(type == "object" and .url == $url) | + [.name // "N/A", .severity // "N/A", .title // "N/A"] | @tsv + ' "$json_file" 2>/dev/null | head -1 || true +} + +fetch_cve_for_ghsa() { + local url="$1" + if [ "$HAS_GH" = false ]; then echo "N/A"; return; fi + local ghsa_id="${url##*/}" + gh api "/advisories/$ghsa_id" 2>/dev/null | jq -r '.cve_id // "N/A"' 2>/dev/null || echo "N/A" +} + +extract_go_ids() { + local json_file="$1" + [ -s "$json_file" ] || return 0 + jq -r 'select(.finding != null) | .finding.osv' "$json_file" 2>/dev/null | sort -u || true +} + +extract_go_detail() { + local json_file="$1" vid="$2" + [ -s "$json_file" ] || return 0 + jq -r --arg id "$vid" ' + select(.osv != null and .osv.id == $id) | .osv | + [ + .id, + (.aliases // [] | join(", ")), + (if .affected then [.affected[].package.name] | unique | join(", ") else "N/A" end), + (.summary // "N/A" | gsub("\n"; " ")) + ] | @tsv + ' "$json_file" 2>/dev/null | head -1 || true +} + +# Returns the lowercase severity tier (critical|high|medium|low|unknown) for a Go OSV entry. +# Reads from database_specific.severity first; falls back to parsing the CVSS base score +# embedded in the vector string via awk when that field is absent. +extract_go_severity() { + local json_file="$1" vid="$2" + [ -s "$json_file" ] || { echo "unknown"; return; } + + local tier + tier=$(jq -r --arg id "$vid" ' + select(.osv != null and .osv.id == $id) | + # Prefer an explicit tier stored by the Go vuln DB + if .osv.database_specific.severity != null then + .osv.database_specific.severity | ascii_downcase + # Fall back to CVSS vector — emit the numeric base score so awk can bucket it + elif (.osv.severity // [] | map(select(.type == "CVSS_V3" or .type == "CVSS_V3_1")) | length) > 0 then + (.osv.severity[] | select(.type == "CVSS_V3" or .type == "CVSS_V3_1") | .score) + else + "unknown" + end + ' "$json_file" 2>/dev/null | head -1) + + case "$tier" in + critical|high|medium|low|unknown) echo "$tier" ;; + # Received a raw CVSS vector — extract the base score digit(s) after "CVSS:x.x/" + # The Go vuln DB stores pre-computed base scores in database_specific; this path + # handles the rare case where only the vector string is available. + CVSS:*) + local base_score + base_score=$(echo "$tier" | awk -F'/' '{ + for (i=1; i<=NF; i++) { + if ($i ~ /^BS:/) { gsub("BS:", "", $i); print $i; exit } + } + print "0" + }') + # If we could not extract BS: field, default to unknown (include it to be safe) + if [[ "$base_score" == "0" ]]; then + echo "unknown" + else + awk -v s="$base_score" 'BEGIN { + if (s+0 >= 9.0) print "critical" + else if (s+0 >= 7.0) print "high" + else if (s+0 >= 4.0) print "medium" + else print "low" + }' + fi + ;; + *) echo "unknown" ;; + esac +} + +# ---- Per-entry processing ---- + +process_entry() { + local entry_index="$1" project="$2" branch="$3" local_dir="$4" rollback="$5" component="$6" + local pdir="$REPO_ROOT/projects/$local_dir" + local padded_index + padded_index=$(printf "%04d" "$entry_index") + local label="[$local_dir]" + + local section_file="$WORK_DIR/sections/${padded_index}.md" + local summary_line="$WORK_DIR/summaries/${padded_index}.txt" + local refs_file="$WORK_DIR/refs/${local_dir}.txt" + + echo "$label Processing $branch..." >&2 + + if [ ! -e "$pdir/.git" ]; then + echo "$label [ERROR] Not found or not a git repo: $pdir" >&2 + exit 1 + fi + + if ! git -C "$pdir" diff --quiet 2>/dev/null || ! git -C "$pdir" diff --cached --quiet 2>/dev/null; then + echo "$label [ERROR] Uncommitted changes in $pdir — refusing to modify working tree" >&2 + exit 1 + fi + + # Save original ref (one file per project, sequential within project so no race) + if [ ! -s "$refs_file" ]; then + local ref + ref=$(git -C "$pdir" symbolic-ref --short HEAD 2>/dev/null || git -C "$pdir" rev-parse HEAD) + echo "${pdir}|${ref}" > "$refs_file" + fi + + local remote + remote=$(resolve_remote "$pdir" "$branch") + if [ -z "$remote" ]; then + echo "$label [ERROR] Cannot find remote for branch $branch in $pdir" >&2 + exit 1 + fi + + echo "$label Fetching $remote/$branch..." >&2 + if ! git -C "$pdir" fetch "$remote" "$branch" 2>/dev/null; then + echo "$label [ERROR] Failed to fetch $remote/$branch" >&2 + exit 1 + fi + + if ! git -C "$pdir" rev-parse "$remote/$branch~$rollback" &>/dev/null; then + echo "$label [ERROR] Branch $branch has fewer than $rollback commits (need $rollback)" >&2 + exit 1 + fi + + local etmp="$WORK_DIR/${local_dir}_${branch}" + mkdir -p "$etmp" + + # --- Capture commit log for the range --- + local commits_file="$etmp/commits.txt" + git -C "$pdir" log --oneline "$remote/$branch~$rollback..$remote/$branch" > "$commits_file" 2>/dev/null || true + + # --- Checkout HEAD (tip of branch) --- + git -C "$pdir" checkout "$remote/$branch" --detach 2>/dev/null + local frontend_dir + frontend_dir=$(detect_frontend_dir "$pdir") + + local npm_head="$etmp/npm_head.json" + touch "$npm_head" + if [ -n "$frontend_dir" ]; then + echo "$label [npm] Auditing $branch at HEAD..." >&2 + (cd "$frontend_dir" && npm audit --json 2>/dev/null) > "$npm_head" || true + fi + + local go_head="$etmp/go_head.json" + touch "$go_head" + if [ -f "$pdir/go.mod" ] && [ "$HAS_GOVULNCHECK" = true ]; then + echo "$label [go] govulncheck $branch at HEAD..." >&2 + (cd "$pdir" && govulncheck -json ./... 2>/dev/null) > "$go_head" || true + fi + + # --- Checkout HEAD~N --- + git -C "$pdir" checkout -- . 2>/dev/null || true + git -C "$pdir" checkout "$remote/$branch~$rollback" --detach 2>/dev/null + local frontend_dir_old + frontend_dir_old=$(detect_frontend_dir "$pdir") + + local npm_old="$etmp/npm_old.json" + touch "$npm_old" + if [ -n "$frontend_dir_old" ]; then + echo "$label [npm] Auditing $branch at HEAD~$rollback..." >&2 + (cd "$frontend_dir_old" && npm install >/dev/null 2>&1 && npm audit --json 2>/dev/null) > "$npm_old" || true + fi + + local go_old="$etmp/go_old.json" + touch "$go_old" + if [ -f "$pdir/go.mod" ] && [ "$HAS_GOVULNCHECK" = true ]; then + echo "$label [go] govulncheck $branch at HEAD~$rollback..." >&2 + (cd "$pdir" && govulncheck -json ./... 2>/dev/null) > "$go_old" || true + fi + + # --- Restore --- + git -C "$pdir" checkout -- . 2>/dev/null || true + local original_ref + original_ref=$(grep "^${pdir}|" "$refs_file" 2>/dev/null | head -1 | cut -d'|' -f2) + git -C "$pdir" checkout "$original_ref" 2>/dev/null || true + + # --- Diff NPM --- + local urls_head="$etmp/urls_head.txt" urls_old="$etmp/urls_old.txt" fixed_npm="$etmp/fixed_npm.txt" + extract_npm_urls "$npm_head" > "$urls_head" + extract_npm_urls "$npm_old" > "$urls_old" + comm -23 "$urls_old" "$urls_head" > "$fixed_npm" 2>/dev/null || true + local npm_count + npm_count=$(wc -l < "$fixed_npm" | tr -d ' ') + + # --- Diff Go --- + local ids_head="$etmp/ids_head.txt" ids_old="$etmp/ids_old.txt" fixed_go="$etmp/fixed_go.txt" + extract_go_ids "$go_head" > "$ids_head" + extract_go_ids "$go_old" > "$ids_old" + comm -23 "$ids_old" "$ids_head" > "$fixed_go" 2>/dev/null || true + local go_count + go_count=$(wc -l < "$fixed_go" | tr -d ' ') + + # --- Filter NPM by severity (high/critical only) --- + # Intermediate files are pre-populated here so the section-writing block + # and the YAML fragment can simply cat/read them without re-looping. + local npm_table_file="$etmp/npm_table.md" + local npm_high_count=0 + touch "$npm_table_file" + if [ -n "$frontend_dir" ] && [ "$npm_count" -gt 0 ]; then + while IFS= read -r url; do + local detail pkg sev title cve + detail=$(extract_npm_detail "$npm_old" "$url") + pkg=$(echo "$detail" | cut -f1) + sev=$(echo "$detail" | cut -f2) + title=$(echo "$detail" | cut -f3) + # Skip anything below high + [[ "$sev" == "high" || "$sev" == "critical" ]] || continue + cve=$(fetch_cve_for_ghsa "$url") + echo "${url}|${cve}" >> "$etmp/cve_cache.txt" + printf '| %s | %s | %s | %s | %s |\n' "$url" "$cve" "$pkg" "$sev" "$title" \ + >> "$npm_table_file" + npm_high_count=$((npm_high_count + 1)) + done < "$fixed_npm" + fi + + # --- Filter Go by severity (high/critical only) --- + local go_table_file="$etmp/go_table.md" + local go_aliases_file="$etmp/go_aliases.txt" + local go_high_count=0 + touch "$go_table_file" "$go_aliases_file" + if [ -f "$pdir/go.mod" ] && [ "$HAS_GOVULNCHECK" = true ] && [ "$go_count" -gt 0 ]; then + while IFS= read -r vid; do + local detail aliases module summary sev_tier display_sev + detail=$(extract_go_detail "$go_old" "$vid") + aliases=$(echo "$detail" | cut -f2) + module=$(echo "$detail" | cut -f3) + summary=$(echo "$detail" | cut -f4) + sev_tier=$(extract_go_severity "$go_old" "$vid") + # Skip medium and low; keep high, critical, and unknown (unknown = no data, include to be safe) + [[ "$sev_tier" == "medium" || "$sev_tier" == "low" ]] && continue + display_sev="${sev_tier^^}" + [[ "$display_sev" == "UNKNOWN" ]] && display_sev="N/A" + printf '| %s | %s | %s | %s | %s |\n' "$vid" "$aliases" "$module" "$display_sev" "$summary" \ + >> "$go_table_file" + echo "$aliases" >> "$go_aliases_file" + go_high_count=$((go_high_count + 1)) + done < "$fixed_go" + fi + + echo "$label $branch: fixed $npm_high_count npm (high/critical), $go_high_count go (high/critical)" >&2 + + # --- Write report section --- + { + echo "## $project ($branch)" + echo "" + + echo "### Commits analyzed" + echo "" + if [ -s "$commits_file" ]; then + while IFS= read -r commit_line; do + echo "- \`${commit_line}\`" + done < "$commits_file" + else + echo "No commits in range." + fi + echo "" + + echo "### NPM Vulnerabilities Fixed" + echo "" + if [ -z "$frontend_dir" ]; then + echo "N/A — no frontend in this project." + elif [ "$npm_high_count" -gt 0 ]; then + echo "| Advisory | CVE | Package | Severity | Title |" + echo "| -------- | --- | ------- | -------- | ----- |" + cat "$npm_table_file" + else + echo "No high/critical NPM vulnerabilities were fixed." + fi + echo "" + + echo "### Go Vulnerabilities Fixed" + echo "" + if [ ! -f "$pdir/go.mod" ]; then + echo "N/A — no go.mod in this project." + elif [ "$HAS_GOVULNCHECK" = false ]; then + echo "Skipped — govulncheck not installed." + elif [ "$go_high_count" -gt 0 ]; then + echo "| ID | CVE/Aliases | Module | Severity | Summary |" + echo "| -- | ----------- | ------ | -------- | ------- |" + cat "$go_table_file" + else + echo "No high/critical Go vulnerabilities were fixed." + fi + echo "" + } > "$section_file" + + echo "$project|$branch|$npm_high_count|$go_high_count|ok" > "$summary_line" + + # --- YAML fragment --- + if [ "$YAML_OUTPUT" = true ]; then + local yaml_file="$WORK_DIR/yaml/${padded_index}.yaml" + { + # NPM CVEs — already filtered to high/critical via cve_cache.txt + if [ -f "$etmp/cve_cache.txt" ]; then + while IFS='|' read -r _url cve; do + if [ "$cve" != "N/A" ] && [ -n "$cve" ]; then + echo " - key: $cve" + echo " component: $component" + fi + done < "$etmp/cve_cache.txt" + fi + # Go CVEs — already filtered to high/critical via go_aliases_file + if [ -s "$go_aliases_file" ]; then + while IFS= read -r aliases; do + IFS=', ' read -ra cve_list <<< "$aliases" + for cve in "${cve_list[@]}"; do + cve=$(echo "$cve" | tr -d ' ') + if [[ "$cve" == CVE-* ]]; then + echo " - key: $cve" + echo " component: $component" + fi + done + done < "$go_aliases_file" + fi + } > "$yaml_file" + fi +} + +# ---- Per-project processing (sequential within project) ---- + +process_project() { + local target_project="$1" + for i in "${!ENTRIES[@]}"; do + local entry="${ENTRIES[$i]}" + local project="${entry%%:*}" + local branch="${entry##*:}" + + if [ "$project" != "$target_project" ]; then + continue + fi + + if [ -n "$FILTER" ] && [[ "$project" != *"$FILTER"* ]]; then + continue + fi + + process_entry "$i" "$project" "$branch" "$project" "${ENTRY_ROLLBACKS[$i]}" "${ENTRY_COMPONENTS[$i]}" + done +} + +# ---- Main: parallel dispatch ---- + +# Build unique project list (preserving order of first appearance) +unique_projects=() +seen_projects="" +for entry in "${ENTRIES[@]}"; do + project="${entry%%:*}" + if [[ "$seen_projects" != *"|${project}|"* ]]; then + unique_projects+=("$project") + seen_projects="${seen_projects}|${project}|" + fi +done + +echo "Starting parallel processing of ${#unique_projects[@]} projects..." >&2 + +pids=() +declare -A pid_project # maps PID → project name for error reporting +for project in "${unique_projects[@]}"; do + if [ -n "$FILTER" ] && [[ "$project" != *"$FILTER"* ]]; then + continue + fi + process_project "$project" & + pid=$! + pids+=("$pid") + pid_project[$pid]="$project" +done + +# Wait for background jobs — kill all remaining and abort on the first failure +for pid in "${pids[@]+"${pids[@]}"}"; do + if ! wait "$pid"; then + echo "[ERROR] Project group '${pid_project[$pid]}' failed — killing remaining jobs and aborting." >&2 + for remaining in "${pids[@]+"${pids[@]}"}"; do + kill "$remaining" 2>/dev/null || true + done + exit 1 + fi +done + +# ---- Assemble report ---- + +{ + echo "# Fixed CVEs Report" + echo "" + echo "Generated: $(date +%Y-%m-%d)" + echo "" +} > "$REPORT" + +# Concatenate sections in original entry order +for section in "$WORK_DIR"/sections/*.md; do + [ -f "$section" ] || continue + [ -s "$section" ] || continue + cat "$section" >> "$REPORT" +done + +# Summary table +{ + echo "## Summary" + echo "" + echo "| Project | Branch | NPM Fixed | Go Fixed | Total | Status |" + echo "| ------- | ------ | --------- | -------- | ----- | ------ |" + for summary in "$WORK_DIR"/summaries/*.txt; do + [ -f "$summary" ] || continue + while IFS='|' read -r p b n g s; do + total=$((n + g)) + echo "| $p | $b | $n | $g | $total | $s |" + done < "$summary" + done + echo "" +} >> "$REPORT" + +# ---- Assemble YAML (if requested) ---- + +if [ "$YAML_OUTPUT" = true ]; then + YAML_REPORT="$SCRIPT_DIR/report.yaml" + echo "cves:" > "$YAML_REPORT" + for yf in "$WORK_DIR"/yaml/*.yaml; do + [ -f "$yf" ] || continue + [ -s "$yf" ] || continue + cat "$yf" >> "$YAML_REPORT" + done + echo "YAML saved to $YAML_REPORT" >&2 +fi + +echo "" >&2 +echo "Report saved to $REPORT" >&2 diff --git a/tasks/script-to-extract-fixed-cves/generate-cve-csv.py b/tasks/script-to-extract-fixed-cves/generate-cve-csv.py new file mode 100644 index 0000000..a8ff3d4 --- /dev/null +++ b/tasks/script-to-extract-fixed-cves/generate-cve-csv.py @@ -0,0 +1,334 @@ +#!/usr/bin/env python3 +""" +generate-cve-csv.py + +Converts report.yaml + report.md into a CVE matrix CSV. + +Column set : union(template CSV CVE columns, report.yaml CVEs), sorted. +Component set: union(template CSV component rows, report.yaml components), + preserving template order then appending extras alphabetically. +Solution row : "Updated in package.json" (NPM) + | "Updated in go.mod" (Go) + | "" if the CVE is from the template but absent in the report. +Data cells : "X" where the (CVE, component) pair exists in report.yaml, else "". + +Usage: + python generate-cve-csv.py [--output PATH] + +Defaults: + --output tasks/script-to-extract-fixed-cves/cve-matrix-output.csv + +All paths are resolved relative to this script's directory. +""" + +import argparse +import csv +import re +import sys +from pathlib import Path + +import yaml # pip install pyyaml + +# --------------------------------------------------------------------------- +# Paths (all relative to the script's own directory) +# --------------------------------------------------------------------------- + +SCRIPT_DIR = Path(__file__).resolve().parent +REPORT_YAML = SCRIPT_DIR / "report.yaml" +REPORT_MD = SCRIPT_DIR / "report.md" +TEMPLATE_CSV = SCRIPT_DIR / "cve-matrix-template.csv" +DEFAULT_OUTPUT = SCRIPT_DIR / "cve-matrix-output.csv" + + +# --------------------------------------------------------------------------- +# Parsing helpers +# --------------------------------------------------------------------------- + + +def parse_report_yaml(path: Path) -> tuple[set[tuple[str, str]], set[str], set[str]]: + """Return (pairs, cves, components) from report.yaml. + + pairs — set of (cve_id, component) strings + cves — unique CVE IDs + components — unique component names + """ + with path.open() as fh: + data = yaml.safe_load(fh) + + pairs: set[tuple[str, str]] = set() + cves: set[str] = set() + components: set[str] = set() + + for entry in data.get("cves", []): + cve = entry.get("key", "").strip() + comp = entry.get("component", "").strip() + if cve and comp: + pairs.add((cve, comp)) + cves.add(cve) + components.add(comp) + + return pairs, cves, components + + +def _pick_module(raw_module: str) -> str: + """Given a comma-separated module list, prefer the first non-stdlib entry.""" + parts = [p.strip() for p in raw_module.split(",") if p.strip()] + non_stdlib = [p for p in parts if p != "stdlib"] + return non_stdlib[0] if non_stdlib else (parts[0] if parts else raw_module) + + +def parse_report_md(path: Path) -> dict[str, tuple[str, str]]: + """Return {cve_id: (package_or_module, ecosystem)} from report.md. + + ecosystem is "npm" or "go". + + For NPM rows : CVE column → Package column. + For Go rows : CVE/Aliases column → Module column (first non-stdlib module). + + When the same CVE appears multiple times with the same package we keep the + first occurrence (all occurrences across branches should be identical). + """ + cve_map: dict[str, tuple[str, str]] = {} + + with path.open() as fh: + lines = fh.readlines() + + # Track which table type we are inside. + # We detect table type from the header row. + in_npm_table = False + in_go_table = False + + # Column indices (0-based, pipe-split, strip whitespace) + npm_cve_col: int | None = None + npm_pkg_col: int | None = None + go_aliases_col: int | None = None + go_module_col: int | None = None + + CVE_PATTERN = re.compile(r"\bCVE-\d{4}-\d+\b") + + def split_row(line: str) -> list[str]: + """Split a markdown table row on '|', drop empty first/last.""" + parts = line.strip().split("|") + return [p.strip() for p in parts[1:-1]] # trim outer empty strings + + def is_separator(line: str) -> bool: + """True for table separator rows like '| --- | --- |'.""" + return bool(re.match(r"^\s*\|[\s\-:|]+\|\s*$", line)) + + for line in lines: + stripped = line.strip() + + # Detect NPM table header: | Advisory | CVE | Package | Severity | Title | + if re.search(r"\|\s*Advisory\s*\|", stripped, re.IGNORECASE): + in_npm_table = True + in_go_table = False + cols = split_row(stripped) + col_lower = [c.lower() for c in cols] + npm_cve_col = next((i for i, c in enumerate(col_lower) if c == "cve"), None) + npm_pkg_col = next( + (i for i, c in enumerate(col_lower) if c == "package"), None + ) + continue + + # Detect Go table header: | ID | CVE/Aliases | Module | ... | Summary | + if re.search(r"\|\s*ID\s*\|", stripped, re.IGNORECASE) and re.search( + r"CVE/Aliases", stripped, re.IGNORECASE + ): + in_go_table = True + in_npm_table = False + cols = split_row(stripped) + col_lower = [c.lower() for c in cols] + go_aliases_col = next( + (i for i, c in enumerate(col_lower) if "aliases" in c), None + ) + go_module_col = next( + (i for i, c in enumerate(col_lower) if c == "module"), None + ) + continue + + # Skip separator rows + if is_separator(stripped): + continue + + # Exit table when we hit a non-table line + if stripped and not stripped.startswith("|"): + in_npm_table = False + in_go_table = False + continue + + if not stripped.startswith("|"): + continue + + # ---- Parse NPM row ---- + if in_npm_table and npm_cve_col is not None and npm_pkg_col is not None: + cells = split_row(stripped) + if len(cells) <= max(npm_cve_col, npm_pkg_col): + continue + cve_raw = cells[npm_cve_col] + pkg = cells[npm_pkg_col] + # CVE cell may be "N/A" or a bare CVE ID + m = CVE_PATTERN.search(cve_raw) + if m and pkg and pkg != "N/A": + cve_id = m.group(0) + if cve_id not in cve_map: + cve_map[cve_id] = (pkg, "npm") + continue + + # ---- Parse Go row ---- + if in_go_table and go_aliases_col is not None and go_module_col is not None: + cells = split_row(stripped) + if len(cells) <= max(go_aliases_col, go_module_col): + continue + aliases_raw = cells[go_aliases_col] + module_raw = cells[go_module_col] + module = _pick_module(module_raw) + for cve_id in CVE_PATTERN.findall(aliases_raw): + if cve_id not in cve_map and module and module != "N/A": + cve_map[cve_id] = (module, "go") + + return cve_map + + +def parse_template_csv(path: Path) -> tuple[list[str], list[str]]: + """Return (cve_columns, component_rows) from the template CSV. + + cve_columns — ordered list of CVE IDs from the header row (col 0 = "Component" skipped). + component_rows — ordered list of component names (row 0 = header skipped, + row 1 = "Solution" skipped, remaining rows). + """ + with path.open(newline="", encoding="utf-8-sig") as fh: + reader = csv.reader(fh) + rows = list(reader) + + if not rows: + return [], [] + + header = rows[0] + cve_columns = [c.strip() for c in header[1:] if c.strip()] + + component_rows: list[str] = [] + for row in rows[1:]: + if not row: + continue + comp = row[0].strip() + if comp.lower() == "solution" or not comp: + continue + component_rows.append(comp) + + return cve_columns, component_rows + + +# --------------------------------------------------------------------------- +# CSV generation +# --------------------------------------------------------------------------- + + +def build_csv( + pairs: set[tuple[str, str]], + yaml_cves: set[str], + yaml_components: set[str], + cve_map: dict[str, tuple[str, str]], + template_cves: list[str], + template_components: list[str], + output_path: Path, +) -> None: + # ---- Column list ---- + # Template CVEs come first in their original template order; any additional + # CVEs from report.yaml that are not already in the template are appended + # alphabetically after. + template_cve_set = set(template_cves) + extra_cves = sorted(yaml_cves - template_cve_set) + all_cves_sorted = template_cves + extra_cves + + # ---- Component list ---- + # Template order first, then any new components from the YAML not in the template. + template_comp_set = set(template_components) + extra_components = sorted(yaml_components - template_comp_set) + all_components = template_components + extra_components + + # ---- Solution row ---- + solution_row: list[str] = ["Solution"] + for cve in all_cves_sorted: + if cve in cve_map: + pkg_or_mod, ecosystem = cve_map[cve] + if ecosystem == "npm": + solution_row.append(f"Updated {pkg_or_mod} in package.json") + else: + solution_row.append(f"Updated {pkg_or_mod} in go.mod") + else: + solution_row.append("") + + # ---- Write ---- + with output_path.open("w", newline="", encoding="utf-8") as fh: + writer = csv.writer(fh) + + # Header + writer.writerow(["Component"] + all_cves_sorted) + + # Solution row + writer.writerow(solution_row) + + # Data rows + for comp in all_components: + row = [comp] + for cve in all_cves_sorted: + row.append("X" if (cve, comp) in pairs else "") + writer.writerow(row) + + print( + f"Written {len(all_components)} components × {len(all_cves_sorted)} CVEs → {output_path}" + ) + + +# --------------------------------------------------------------------------- +# Main +# --------------------------------------------------------------------------- + + +def main() -> None: + parser = argparse.ArgumentParser( + description=__doc__, formatter_class=argparse.RawDescriptionHelpFormatter + ) + parser.add_argument( + "--output", + type=Path, + default=DEFAULT_OUTPUT, + help=f"Output CSV path (default: {DEFAULT_OUTPUT})", + ) + args = parser.parse_args() + + # Validate inputs + for p in (REPORT_YAML, REPORT_MD, TEMPLATE_CSV): + if not p.exists(): + print(f"ERROR: required file not found: {p}", file=sys.stderr) + sys.exit(1) + + print(f"Parsing {REPORT_YAML.name} …") + pairs, yaml_cves, yaml_components = parse_report_yaml(REPORT_YAML) + print( + f" {len(pairs)} (CVE, component) pairs, {len(yaml_cves)} unique CVEs, {len(yaml_components)} unique components" + ) + + print(f"Parsing {REPORT_MD.name} …") + cve_map = parse_report_md(REPORT_MD) + print(f" {len(cve_map)} CVEs with solution info") + + print(f"Parsing template {TEMPLATE_CSV.name} …") + template_cves, template_components = parse_template_csv(TEMPLATE_CSV) + print( + f" {len(template_cves)} template CVE columns, {len(template_components)} template components" + ) + + build_csv( + pairs=pairs, + yaml_cves=yaml_cves, + yaml_components=yaml_components, + cve_map=cve_map, + template_cves=template_cves, + template_components=template_components, + output_path=args.output, + ) + + +if __name__ == "__main__": + main() diff --git a/tasks/script-to-extract-fixed-cves/plan.md b/tasks/script-to-extract-fixed-cves/plan.md new file mode 100644 index 0000000..5980415 --- /dev/null +++ b/tasks/script-to-extract-fixed-cves/plan.md @@ -0,0 +1,358 @@ +# Plan: Script to Extract Fixed CVEs + +## Problem + +After dependency update commits are cherry-picked to release branches, we need a way to identify which CVEs were fixed by those updates. Currently +this requires manually running `npm audit` and `govulncheck` before and after the commits, then comparing the results — tedious and error-prone across +14 project/branch combinations. The script automates this: for each project+branch pair, it diffs the vulnerability state at HEAD vs HEAD~3 and +produces a markdown report listing the CVEs that were resolved. + +## Current State + +| Component | File / Location | Current Behavior | +| ---------------------------- | ---------------------------------------- | ------------------------------------------------------------------------------------------------------- | +| perses-operator | `projects/perses-operator/` | Go-only project. Branch `release-coo-1.5` on `rhobs` remote. No frontend. | +| monitoring-plugin | `projects/monitoring-plugin/` | Go backend + frontend in `web/`. Release branches `release-coo-ocp-4.{15,19,22}` on `upstream` remote. | +| logging-view-plugin | `projects/logging-view-plugin/` | Go backend + frontend in `web/`. Release branches `release-coo-ocp-4.{12,15,22}` on `upstream` remote. | +| distributed-tracing-plugin | `projects/distributed-tracing-plugin/` | Go backend + frontend in `web/`. Release branches `release-coo-ocp-4.{12,15,19,22}` on `origin` remote. | +| troubleshooting-panel-plugin | `projects/troubleshooting-panel-plugin/` | Go backend + frontend in `web/`. Release branches `release-coo-ocp-4.{19,22}` on `origin` remote. | +| Script location | `tasks/script-to-extract-fixed-cves/` | Only `spec.md` exists. No script yet. | + +### Remote/Branch Mapping + +The script must resolve the correct remote for each branch since projects use different remote names: + +| Project | Remote | Branch pattern | +| ---------------------------- | ---------- | --------------------- | +| perses-operator | `rhobs` | `release-coo-1.5` | +| monitoring-plugin | `upstream` | `release-coo-ocp-4.*` | +| logging-view-plugin | `upstream` | `release-coo-ocp-4.*` | +| distributed-tracing-plugin | `origin` | `release-coo-ocp-4.*` | +| troubleshooting-panel-plugin | `origin` | `release-coo-ocp-4.*` | + +### Frontend Location + +All UI plugins have their `package.json` in `web/`, not the project root. The perses-operator has no frontend at all. The script must auto-detect the +frontend directory by checking for `web/package.json` first, then falling back to root `package.json`. + +## Changes + +### Phase 1: Core Script — Git Operations and Project Loop + +**Dependency:** None **Parallel with:** None + +#### Files Modified + +| File | Change | +| ---------------------------------------------------------- | --------------------------- | +| `tasks/script-to-extract-fixed-cves/extract-fixed-cves.sh` | New file — main bash script | + +#### Details + +Create a bash script that: + +1. **Defines the project/branch configuration as an array:** + +```bash +ENTRIES=( + "perses-operator:release-coo-1.5" + "monitoring-plugin:release-coo-ocp-4.15" + "monitoring-plugin:release-coo-ocp-4.19" + "monitoring-plugin:release-coo-ocp-4.22" + "logging-view-plugin:release-coo-ocp-4.12" + "logging-view-plugin:release-coo-ocp-4.15" + "logging-view-plugin:release-coo-ocp-4.22" + "distributed-tracing-console-plugin:release-coo-ocp-4.12" + "distributed-tracing-console-plugin:release-coo-ocp-4.15" + "distributed-tracing-console-plugin:release-coo-ocp-4.19" + "distributed-tracing-console-plugin:release-coo-ocp-4.22" + "troubleshooting-panel-console-plugin:release-coo-ocp-4.19" + "troubleshooting-panel-console-plugin:release-coo-ocp-4.22" +) +``` + +Note: The spec uses repository names (e.g., `distributed-tracing-console-plugin`) but the local submodule directories use shorter names (e.g., +`distributed-tracing-plugin`). The script must map repo names → local directory names: + +```bash +get_local_dir() { + case "$1" in + distributed-tracing-console-plugin) echo "distributed-tracing-plugin" ;; + troubleshooting-panel-console-plugin) echo "troubleshooting-panel-plugin" ;; + *) echo "$1" ;; + esac +} +``` + +2. **For each entry, resolves the remote that tracks the branch:** + +```bash +resolve_remote() { + local project_dir="$1" branch="$2" + git -C "$project_dir" branch -r | grep -E "/${branch}$" | head -1 | cut -d'/' -f1 | tr -d ' ' +} +``` + +3. **Fetches the remote, checks out the branch at detached HEAD, and records the original ref for restoration:** + +```bash +original_ref=$(git -C "$project_dir" rev-parse HEAD) +git -C "$project_dir" fetch "$remote" "$branch" +git -C "$project_dir" checkout "$remote/$branch" --detach +``` + +4. **After running audits (Phase 2), restores the original state:** + +```bash +git -C "$project_dir" checkout "$original_ref" --detach +git -C "$project_dir" checkout - # or restore to original branch +``` + +#### Phase 1 Verification + +- Run `bash -n tasks/script-to-extract-fixed-cves/extract-fixed-cves.sh` to verify syntax +- Verify the remote resolution logic works: `git -C ./projects/monitoring-plugin branch -r | grep -E "/release-coo-ocp-4.15$"` + +--- + +### Phase 2: NPM Audit Diff Logic + +**Dependency:** Phase 1 **Parallel with:** Phase 3 (different concern, same file) + +#### Files Modified + +| File | Change | +| ---------------------------------------------------------- | ---------------------------- | +| `tasks/script-to-extract-fixed-cves/extract-fixed-cves.sh` | Add npm audit diff functions | + +#### Details + +Add functions to detect the frontend directory, run `npm audit` at two points, and diff the results. + +##### Frontend Directory Detection + +```bash +detect_frontend_dir() { + local project_dir="$1" + if [ -f "$project_dir/web/package.json" ]; then + echo "$project_dir/web" + elif [ -f "$project_dir/package.json" ]; then + echo "$project_dir" + else + echo "" + fi +} +``` + +##### NPM Audit Diff + +```bash +run_npm_audit() { + local frontend_dir="$1" output_file="$2" + (cd "$frontend_dir" && npm install --ignore-scripts 2>/dev/null && npm audit --json 2>/dev/null) > "$output_file" +} + +extract_npm_cves() { + local audit_json="$1" + # npm audit --json outputs vulnerabilities keyed by package name + # Each vulnerability has a "via" array containing objects with "url" fields (advisory URLs containing CVE refs) + jq -r '.vulnerabilities | to_entries[] | .value.via[]? | + if type == "object" then .url // empty else empty end' "$audit_json" | + sort -u +} +``` + +The diff logic: + +1. At HEAD: run `npm audit --json` → `audit_head.json` +2. At HEAD~3: run `npm install --ignore-scripts` then `npm audit --json` → `audit_head3.json` +3. Extract advisory URLs from both +4. Use `comm -23` to find URLs in HEAD~3 but not in HEAD (= fixed) + +For each fixed advisory URL, also extract the CVE ID, severity, package name, and vulnerability title from the HEAD~3 audit JSON for the report. + +#### Phase 2 Verification + +- Test against monitoring-plugin on `release-coo-ocp-4.22` to verify npm audit output parsing +- Verify `jq` correctly extracts advisory URLs from npm audit JSON + +--- + +### Phase 3: govulncheck Diff Logic + +**Dependency:** Phase 1 **Parallel with:** Phase 2 (different concern, same file) + +#### Files Modified + +| File | Change | +| ---------------------------------------------------------- | ------------------------------ | +| `tasks/script-to-extract-fixed-cves/extract-fixed-cves.sh` | Add govulncheck diff functions | + +#### Details + +Add functions to run `govulncheck` at two points and diff the results. This applies to all projects since they all have `go.mod`. + +##### govulncheck Diff + +```bash +run_govulncheck() { + local project_dir="$1" output_file="$2" + (cd "$project_dir" && govulncheck -json ./... 2>/dev/null) > "$output_file" +} + +extract_go_vulns() { + local vuln_json="$1" + # govulncheck -json outputs one JSON object per line with "finding" entries + # Each finding has an "osv" field with the vulnerability ID (e.g., GO-2024-3321) + jq -r 'select(.finding != null) | .finding.osv' "$vuln_json" | sort -u +} +``` + +The diff logic mirrors NPM: + +1. At HEAD: run `govulncheck -json ./...` → `govulncheck_head.json` +2. At HEAD~3: run `govulncheck -json ./...` → `govulncheck_head3.json` +3. Extract vulnerability IDs from both +4. Use `comm -23` to find IDs in HEAD~3 but not in HEAD (= fixed) + +For each fixed vulnerability, also extract the aliases (CVE IDs), affected module, and summary from the HEAD~3 output for the report. The +`govulncheck -json` output includes `osv` entries with full details: + +```bash +extract_go_vuln_details() { + local vuln_json="$1" vuln_id="$2" + jq -r --arg id "$vuln_id" ' + select(.osv != null and .osv.id == $id) | + .osv | {id, aliases: (.aliases // []), summary, affected: [.affected[]?.package.name]} + ' "$vuln_json" +} +``` + +#### Phase 3 Verification + +- Test against perses-operator on `release-coo-1.5` to verify govulncheck output parsing +- Verify `jq` correctly extracts OSV IDs from govulncheck JSON + +--- + +### Phase 4: Markdown Report Generation + +**Dependency:** Phase 2, Phase 3 **Parallel with:** None + +#### Files Modified + +| File | Change | +| ---------------------------------------------------------- | ------------------------------ | +| `tasks/script-to-extract-fixed-cves/extract-fixed-cves.sh` | Add report generation function | + +#### Details + +After processing all entries, generate a markdown report at `tasks/script-to-extract-fixed-cves/report.md` with the following structure: + +```markdown +# Fixed CVEs Report + +Generated: 2026-06-29 + +## monitoring-plugin (release-coo-ocp-4.15) + +### NPM Vulnerabilities Fixed + +| Advisory | CVE | Package | Severity | Title | +| --------------------------------------- | ------------- | ------- | -------- | ------------------- | +| https://github.com/advisories/GHSA-xxxx | CVE-2024-xxxx | lodash | high | Prototype Pollution | + +### Go Vulnerabilities Fixed + +| ID | CVE | Module | Summary | +| ------------ | ------------- | ---------------- | ------------------ | +| GO-2024-3321 | CVE-2024-xxxx | golang.org/x/net | HTTP/2 rapid reset | + +## monitoring-plugin (release-coo-ocp-4.19) + +... + +## Summary + +| Project | Branch | NPM Fixed | Go Fixed | Total | +| ----------------- | -------------------- | --------- | -------- | ----- | +| monitoring-plugin | release-coo-ocp-4.15 | 3 | 1 | 4 | +| ... | ... | ... | ... | ... | +``` + +The script writes the report incrementally: each project/branch appends its section, then the summary table is generated at the end from the collected +counts. + +#### Phase 4 Verification + +- Run the full script and verify the generated `report.md` is valid markdown +- Check that every project/branch entry from the spec appears in the report (even if zero CVEs fixed) + +--- + +### Phase 5: Error Handling and Cleanup + +**Dependency:** Phase 4 **Parallel with:** None + +#### Files Modified + +| File | Change | +| ---------------------------------------------------------- | ----------------------------------- | +| `tasks/script-to-extract-fixed-cves/extract-fixed-cves.sh` | Add cleanup trap and error handling | + +#### Details + +1. **Trap for cleanup**: Ensure the working directory of each submodule is restored even if the script fails mid-execution. + +```bash +cleanup() { + for project_dir in "${TOUCHED_DIRS[@]}"; do + git -C "$project_dir" checkout - 2>/dev/null || true + git -C "$project_dir" clean -fd 2>/dev/null || true + done + rm -rf "$TMPDIR" +} +trap cleanup EXIT +``` + +2. **Temp directory for intermediate files**: Use `mktemp -d` for all audit JSON files. + +3. **Skip missing tools gracefully**: If `govulncheck` is not installed, log a warning and skip Go analysis (npm is assumed to be present). If `jq` is + missing, fail with a clear error since it's required. + +4. **Skip projects without Go/frontend**: If a project has no `go.mod`, skip govulncheck. If no `package.json` is found, skip npm audit. + +5. **Progress logging**: Print progress to stderr so stdout remains clean for piping. + +#### Phase 5 Verification + +- Verify cleanup works by killing the script mid-run and checking that submodule working trees are restored +- Verify the script handles missing `govulncheck` gracefully + +## PR Strategy + +| PR | Repository | Branch | Description | Dependencies | +| -- | ---------- | ------ | --------------------------------------------------------------------------- | ------------ | +| 1 | ai-sdlc | main | Add `extract-fixed-cves.sh` script in `tasks/script-to-extract-fixed-cves/` | None | + +Single PR since the script is self-contained in the task directory and doesn't modify any project submodule code. + +## Verification + +- **Rollback + npm audit**: Run the script against `monitoring-plugin:release-coo-ocp-4.22` and verify it detects CVEs that were fixed in the recent + `update-vulnerable-dependencies-26-06-2026` commits. +- **Rollback + govulncheck**: Run the script against `perses-operator:release-coo-1.5` and verify Go vulnerability diff works. +- **Multiple projects in a loop**: Run the full script with all 13 entries and verify the report contains a section for each. +- **Frontend in different directory**: Verify the script correctly finds `web/package.json` for the UI plugins and skips frontend analysis for + perses-operator. +- **Markdown report**: Verify the generated report is valid markdown with proper tables and summary. + +## Risks + +| Risk | Impact | Mitigation | +| ---------------------------------------------------------------------------------- | ----------------------------------------------- | ------------------------------------------------------------------------------------------ | +| `npm install` at HEAD~3 may fail if Node version is incompatible with old lockfile | Script aborts for that entry, no CVE data | Use `--ignore-scripts` and `--legacy-peer-deps` flags; catch errors and report as warnings | +| `govulncheck` requires Go to be installed and modules to build | Missing Go vulns for some entries | Check for `govulncheck` availability before running; skip with warning if missing | +| Checking out branches modifies submodule working trees | Uncommitted changes in submodules could be lost | Save and restore original ref; refuse to run if there are uncommitted changes | +| npm audit JSON format varies between npm versions | Parsing breaks | Use `npm audit --json` which has been stable since npm 7; document minimum npm version | +| Large number of entries (13) makes full run slow due to `npm install` at each | Script takes 10+ minutes | Add `--project` flag to run for a single project; show progress per entry | diff --git a/tasks/script-to-extract-fixed-cves/report.md b/tasks/script-to-extract-fixed-cves/report.md new file mode 100644 index 0000000..93e8f0e --- /dev/null +++ b/tasks/script-to-extract-fixed-cves/report.md @@ -0,0 +1,537 @@ +# Fixed CVEs Report + +Generated: 2026-06-29 + +## perses-operator (release-coo-1.5) + +### Commits analyzed + +- `f7d3b85 [FORK] downgrade to go 1.26.3 to match konflux` +- `7df0910 Merge pull request #8 from rhobs/optimize-watcher-mermory-usage` +- `9cbc2dc Merge pull request #10 from perses/fix-vulnerable-dependencies` +- `ffe645d [FORK] fix vulnerable dependencies` +- `31fee9b [ENHANCEMENT] use only metadata to watch for resources to optimize memory consumption` + +### NPM Vulnerabilities Fixed + +N/A — no frontend in this project. + +### Go Vulnerabilities Fixed + +No high/critical Go vulnerabilities were fixed. + +## monitoring-plugin (release-coo-ocp-4.15) + +### Commits analyzed + +- `524eb72 Merge pull request #1018 from jgbernalp/update-vulnerable-dependencies-4.15-26-06-2026` +- `02e9fbd fix: update vulnerable dependencies` +- `a3ff6a4 Merge pull request #1011 from openshift-cherrypick-robot/cherry-pick-1009-to-release-coo-ocp-4.15` +- `f13fb8e fix(perses): fall back to metadata.name when dashboard display name is missing` + +### NPM Vulnerabilities Fixed + +| Advisory | CVE | Package | Severity | Title | +| -------- | --- | ------- | -------- | ----- | +| https://github.com/advisories/GHSA-22p9-wv53-3rq4 | CVE-2026-48801 | linkify-it | high | LinkifyIt#match scan loop has quadratic algorithmic complexity | +| https://github.com/advisories/GHSA-96hv-2xvq-fx4p | CVE-2026-48779 | ws | high | ws: Memory exhaustion DoS from tiny fragments and data chunks | +| https://github.com/advisories/GHSA-hm92-r4w5-c3mj | CVE-2026-6734 | undici | high | undici vulnerable to cross-origin request routing via SOCKS5 proxy pool reuse | +| https://github.com/advisories/GHSA-hmw2-7cc7-3qxx | CVE-2026-12143 | form-data | high | form-data: CRLF injection in form-data via unescaped multipart field names and filenames | +| https://github.com/advisories/GHSA-ph9p-34f9-6g65 | CVE-2026-44705 | tmp | high | tmp has Path Traversal via unsanitized prefix/postfix that enables directory escape | +| https://github.com/advisories/GHSA-vmh5-mc38-953g | CVE-2026-9697 | undici | high | undici vulnerable to TLS certificate validation bypass via dropped requestTls in SOCKS5 ProxyAgent | +| https://github.com/advisories/GHSA-vxpw-j846-p89q | CVE-2026-12151 | undici | high | undici WebSocket client vulnerable to denial of service via fragment count bypass | +| https://github.com/advisories/GHSA-w7jw-789q-3m8p | CVE-2026-9277 | shell-quote | critical | shell-quote quote() does not escape newlines in object .op values | + +### Go Vulnerabilities Fixed + +| ID | CVE/Aliases | Module | Severity | Summary | +| -- | ----------- | ------ | -------- | ------- | +| GO-2025-3488 | CVE-2025-22868 | golang.org/x/oauth2 | N/A | Unexpected memory consumption during token parsing in golang.org/x/oauth2 | +| GO-2025-3503 | CVE-2025-22870, GHSA-qxp5-gwg8-xv66 | golang.org/x/net, stdlib | N/A | HTTP Proxy bypass using IPv6 Zone IDs in golang.org/x/net | +| GO-2025-3595 | CVE-2025-22872 | golang.org/x/net | N/A | Incorrect Neutralization of Input During Web Page Generation in x/net in golang.org/x/net | +| GO-2026-4440 | CVE-2025-47911 | golang.org/x/net | N/A | Quadratic parsing complexity in golang.org/x/net/html | +| GO-2026-4441 | CVE-2025-58190 | golang.org/x/net | N/A | Infinite parsing loop in golang.org/x/net | +| GO-2026-4918 | CVE-2026-33814 | golang.org/x/net, stdlib | N/A | Infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE in net/http/internal/http2 in golang.org/x/net | +| GO-2026-5024 | CVE-2026-39824 | golang.org/x/sys | N/A | Invoking integer overflow in NewNTUnicodeString in golang.org/x/sys/windows | +| GO-2026-5025 | CVE-2026-42506 | golang.org/x/net | N/A | Invoking incorrect handling of namespaced elements in foreign content in golang.org/x/net/html | +| GO-2026-5026 | CVE-2026-39821 | golang.org/x/net | N/A | Invoking failure to reject ASCII-only Punycode-encoded labels in golang.org/x/net/idna | +| GO-2026-5027 | CVE-2026-42502 | golang.org/x/net | N/A | Invoking incorrect handling of HTML elements in foreign content in golang.org/x/net/html | +| GO-2026-5028 | CVE-2026-25680 | golang.org/x/net | N/A | Invoking denial of service when parsing arbitrary HTML in golang.org/x/net/html | +| GO-2026-5029 | CVE-2026-25681 | golang.org/x/net | N/A | Invoking incorrect handling of character references in DOCTYPE nodes in golang.org/x/net/html | +| GO-2026-5030 | CVE-2026-27136 | golang.org/x/net | N/A | Invoking duplicate attributes can cause XSS in golang.org/x/net/html | + +## monitoring-plugin (release-coo-ocp-4.19) + +### Commits analyzed + +- `b4c81a8 Merge pull request #1016 from jgbernalp/update-vulnerable-dependencies-4.19-26-06-2026` +- `f119969 fix: update vulnerable dependencies` +- `f1f7895 Merge pull request #1009 from openshift-cherrypick-robot/cherry-pick-1005-to-release-coo-ocp-4.19` +- `c1eaf8e fix(perses): fall back to metadata.name when dashboard display name is missing` + +### NPM Vulnerabilities Fixed + +| Advisory | CVE | Package | Severity | Title | +| -------- | --- | ------- | -------- | ----- | +| https://github.com/advisories/GHSA-22p9-wv53-3rq4 | CVE-2026-48801 | linkify-it | high | LinkifyIt#match scan loop has quadratic algorithmic complexity | +| https://github.com/advisories/GHSA-96hv-2xvq-fx4p | CVE-2026-48779 | ws | high | ws: Memory exhaustion DoS from tiny fragments and data chunks | +| https://github.com/advisories/GHSA-hm92-r4w5-c3mj | CVE-2026-6734 | undici | high | undici vulnerable to cross-origin request routing via SOCKS5 proxy pool reuse | +| https://github.com/advisories/GHSA-hmw2-7cc7-3qxx | CVE-2026-12143 | form-data | high | form-data: CRLF injection in form-data via unescaped multipart field names and filenames | +| https://github.com/advisories/GHSA-ph9p-34f9-6g65 | CVE-2026-44705 | tmp | high | tmp has Path Traversal via unsanitized prefix/postfix that enables directory escape | +| https://github.com/advisories/GHSA-vmh5-mc38-953g | CVE-2026-9697 | undici | high | undici vulnerable to TLS certificate validation bypass via dropped requestTls in SOCKS5 ProxyAgent | +| https://github.com/advisories/GHSA-vxpw-j846-p89q | CVE-2026-12151 | undici | high | undici WebSocket client vulnerable to denial of service via fragment count bypass | +| https://github.com/advisories/GHSA-w7jw-789q-3m8p | CVE-2026-9277 | shell-quote | critical | shell-quote quote() does not escape newlines in object .op values | + +### Go Vulnerabilities Fixed + +| ID | CVE/Aliases | Module | Severity | Summary | +| -- | ----------- | ------ | -------- | ------- | +| GO-2025-3488 | CVE-2025-22868 | golang.org/x/oauth2 | N/A | Unexpected memory consumption during token parsing in golang.org/x/oauth2 | +| GO-2025-3503 | CVE-2025-22870, GHSA-qxp5-gwg8-xv66 | golang.org/x/net, stdlib | N/A | HTTP Proxy bypass using IPv6 Zone IDs in golang.org/x/net | +| GO-2025-3595 | CVE-2025-22872 | golang.org/x/net | N/A | Incorrect Neutralization of Input During Web Page Generation in x/net in golang.org/x/net | +| GO-2026-4440 | CVE-2025-47911 | golang.org/x/net | N/A | Quadratic parsing complexity in golang.org/x/net/html | +| GO-2026-4441 | CVE-2025-58190 | golang.org/x/net | N/A | Infinite parsing loop in golang.org/x/net | +| GO-2026-4918 | CVE-2026-33814 | golang.org/x/net, stdlib | N/A | Infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE in net/http/internal/http2 in golang.org/x/net | +| GO-2026-5024 | CVE-2026-39824 | golang.org/x/sys | N/A | Invoking integer overflow in NewNTUnicodeString in golang.org/x/sys/windows | +| GO-2026-5025 | CVE-2026-42506 | golang.org/x/net | N/A | Invoking incorrect handling of namespaced elements in foreign content in golang.org/x/net/html | +| GO-2026-5026 | CVE-2026-39821 | golang.org/x/net | N/A | Invoking failure to reject ASCII-only Punycode-encoded labels in golang.org/x/net/idna | +| GO-2026-5027 | CVE-2026-42502 | golang.org/x/net | N/A | Invoking incorrect handling of HTML elements in foreign content in golang.org/x/net/html | +| GO-2026-5028 | CVE-2026-25680 | golang.org/x/net | N/A | Invoking denial of service when parsing arbitrary HTML in golang.org/x/net/html | +| GO-2026-5029 | CVE-2026-25681 | golang.org/x/net | N/A | Invoking incorrect handling of character references in DOCTYPE nodes in golang.org/x/net/html | +| GO-2026-5030 | CVE-2026-27136 | golang.org/x/net | N/A | Invoking duplicate attributes can cause XSS in golang.org/x/net/html | + +## monitoring-plugin (release-coo-ocp-4.22) + +### Commits analyzed + +- `c6e230f Merge pull request #1017 from jgbernalp/update-vulnerable-dependencies-4.22-26-06-2026` +- `bf0f8ab fix: update vulnerable dependencies` +- `f2d03bd Merge pull request #1005 from openshift-cherrypick-robot/cherry-pick-998-to-release-coo-ocp-4.22` +- `8fd3eb2 fix(perses): fall back to metadata.name when dashboard display name is missing` + +### NPM Vulnerabilities Fixed + +| Advisory | CVE | Package | Severity | Title | +| -------- | --- | ------- | -------- | ----- | +| https://github.com/advisories/GHSA-22p9-wv53-3rq4 | CVE-2026-48801 | linkify-it | high | LinkifyIt#match scan loop has quadratic algorithmic complexity | +| https://github.com/advisories/GHSA-96hv-2xvq-fx4p | CVE-2026-48779 | ws | high | ws: Memory exhaustion DoS from tiny fragments and data chunks | +| https://github.com/advisories/GHSA-fv7c-fp4j-7gwp | CVE-2026-44728 | @babel/plugin-transform-modules-systemjs | high | @babel/plugin-transform-modules-systemjs generates arbitrary code when compiling malicious input | +| https://github.com/advisories/GHSA-hm92-r4w5-c3mj | CVE-2026-6734 | undici | high | undici vulnerable to cross-origin request routing via SOCKS5 proxy pool reuse | +| https://github.com/advisories/GHSA-hmw2-7cc7-3qxx | CVE-2026-12143 | form-data | high | form-data: CRLF injection in form-data via unescaped multipart field names and filenames | +| https://github.com/advisories/GHSA-ph9p-34f9-6g65 | CVE-2026-44705 | tmp | high | tmp has Path Traversal via unsanitized prefix/postfix that enables directory escape | +| https://github.com/advisories/GHSA-q3j6-qgpj-74h6 | CVE-2026-6321 | fast-uri | high | fast-uri vulnerable to path traversal via percent-encoded dot segments | +| https://github.com/advisories/GHSA-v39h-62p7-jpjc | CVE-2026-6322 | fast-uri | high | fast-uri vulnerable to host confusion via percent-encoded authority delimiters | +| https://github.com/advisories/GHSA-vmh5-mc38-953g | CVE-2026-9697 | undici | high | undici vulnerable to TLS certificate validation bypass via dropped requestTls in SOCKS5 ProxyAgent | +| https://github.com/advisories/GHSA-vxpw-j846-p89q | CVE-2026-12151 | undici | high | undici WebSocket client vulnerable to denial of service via fragment count bypass | +| https://github.com/advisories/GHSA-w7jw-789q-3m8p | CVE-2026-9277 | shell-quote | critical | shell-quote quote() does not escape newlines in object .op values | + +### Go Vulnerabilities Fixed + +| ID | CVE/Aliases | Module | Severity | Summary | +| -- | ----------- | ------ | -------- | ------- | +| GO-2025-3488 | CVE-2025-22868 | golang.org/x/oauth2 | N/A | Unexpected memory consumption during token parsing in golang.org/x/oauth2 | +| GO-2025-3503 | CVE-2025-22870, GHSA-qxp5-gwg8-xv66 | golang.org/x/net, stdlib | N/A | HTTP Proxy bypass using IPv6 Zone IDs in golang.org/x/net | +| GO-2025-3595 | CVE-2025-22872 | golang.org/x/net | N/A | Incorrect Neutralization of Input During Web Page Generation in x/net in golang.org/x/net | +| GO-2026-4440 | CVE-2025-47911 | golang.org/x/net | N/A | Quadratic parsing complexity in golang.org/x/net/html | +| GO-2026-4441 | CVE-2025-58190 | golang.org/x/net | N/A | Infinite parsing loop in golang.org/x/net | +| GO-2026-4918 | CVE-2026-33814 | golang.org/x/net, stdlib | N/A | Infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE in net/http/internal/http2 in golang.org/x/net | +| GO-2026-5024 | CVE-2026-39824 | golang.org/x/sys | N/A | Invoking integer overflow in NewNTUnicodeString in golang.org/x/sys/windows | +| GO-2026-5025 | CVE-2026-42506 | golang.org/x/net | N/A | Invoking incorrect handling of namespaced elements in foreign content in golang.org/x/net/html | +| GO-2026-5026 | CVE-2026-39821 | golang.org/x/net | N/A | Invoking failure to reject ASCII-only Punycode-encoded labels in golang.org/x/net/idna | +| GO-2026-5027 | CVE-2026-42502 | golang.org/x/net | N/A | Invoking incorrect handling of HTML elements in foreign content in golang.org/x/net/html | +| GO-2026-5028 | CVE-2026-25680 | golang.org/x/net | N/A | Invoking denial of service when parsing arbitrary HTML in golang.org/x/net/html | +| GO-2026-5029 | CVE-2026-25681 | golang.org/x/net | N/A | Invoking incorrect handling of character references in DOCTYPE nodes in golang.org/x/net/html | +| GO-2026-5030 | CVE-2026-27136 | golang.org/x/net | N/A | Invoking duplicate attributes can cause XSS in golang.org/x/net/html | + +## logging-view-plugin (release-coo-ocp-4.12) + +### Commits analyzed + +- `5d3f32f Merge pull request #388 from jgbernalp/update-vulnerable-dependencies-4.12-26-06-2026` +- `72c3401 fix: update vulnerable dependencies` +- `8bc9d84 Merge pull request #384 from jgbernalp/fix-load-more-and-time-precision-coo-4.12` +- `1085301 refactor: add nano seconds unit to variable names, use nanoseconds in all loki client functions` +- `6df12dd refactor: remove unused currentTime` +- `a45ad60 bugfix: add nanosecond precision to load more calculation to avoid loosing logs on high volume results` + +### NPM Vulnerabilities Fixed + +| Advisory | CVE | Package | Severity | Title | +| -------- | --- | ------- | -------- | ----- | +| https://github.com/advisories/GHSA-2328-f5f3-gj25 | CVE-2026-33896 | node-forge | high | Forge has a basicConstraints bypass in its certificate chain verification (RFC 5280 violation) | +| https://github.com/advisories/GHSA-25h7-pfq9-p65f | CVE-2026-32141 | flatted | high | flatted vulnerable to unbounded recursion DoS in parse() revive phase | +| https://github.com/advisories/GHSA-2w6w-674q-4c4q | CVE-2026-33937 | handlebars | critical | Handlebars.js has JavaScript Injection via AST Type Confusion | +| https://github.com/advisories/GHSA-37ch-88jc-xwx2 | CVE-2026-4867 | path-to-regexp | high | path-to-regexp vulnerable to Regular Expression Denial of Service via multiple route parameters | +| https://github.com/advisories/GHSA-3mfm-83xf-c92r | CVE-2026-33938 | handlebars | high | Handlebars.js has JavaScript Injection via AST Type Confusion by tampering @partial-block | +| https://github.com/advisories/GHSA-5c6j-r48x-rmvq | N/A | serialize-javascript | high | Serialize JavaScript is Vulnerable to RCE via RegExp.flags and Date.prototype.toISOString() | +| https://github.com/advisories/GHSA-5m6q-g25r-mvwx | CVE-2026-33891 | node-forge | high | Forge has Denial of Service via Infinite Loop in BigInteger.modInverse() with Zero Input | +| https://github.com/advisories/GHSA-96hv-2xvq-fx4p | CVE-2026-48779 | ws | high | ws: Memory exhaustion DoS from tiny fragments and data chunks | +| https://github.com/advisories/GHSA-9cx6-37pm-9jff | CVE-2026-33939 | handlebars | high | Handlebars.js has Denial of Service via Malformed Decorator Syntax in Template Compilation | +| https://github.com/advisories/GHSA-c27g-q93r-2cwf | CVE-2024-52011 | launch-editor | high | launch-editor vulnerable to command injection via the crafted request on Windows | +| https://github.com/advisories/GHSA-c2c7-rcm5-vvqj | CVE-2026-33671 | picomatch | high | Picomatch has a ReDoS vulnerability via extglob quantifiers | +| https://github.com/advisories/GHSA-f269-vfmq-vjvj | CVE-2026-1528 | undici | high | Undici: Malicious WebSocket 64-bit length overflows parser and crashes the client | +| https://github.com/advisories/GHSA-fv7c-fp4j-7gwp | CVE-2026-44728 | @babel/plugin-transform-modules-systemjs | high | @babel/plugin-transform-modules-systemjs generates arbitrary code when compiling malicious input | +| https://github.com/advisories/GHSA-hmw2-7cc7-3qxx | CVE-2026-12143 | form-data | high | form-data: CRLF injection in form-data via unescaped multipart field names and filenames | +| https://github.com/advisories/GHSA-ph9p-34f9-6g65 | CVE-2026-44705 | tmp | high | tmp has Path Traversal via unsanitized prefix/postfix that enables directory escape | +| https://github.com/advisories/GHSA-ppp5-5v6c-4jwp | CVE-2026-33894 | node-forge | high | Forge has signature forgery in RSA-PKCS due to ASN.1 extra field | +| https://github.com/advisories/GHSA-q3j6-qgpj-74h6 | CVE-2026-6321 | fast-uri | high | fast-uri vulnerable to path traversal via percent-encoded dot segments | +| https://github.com/advisories/GHSA-q67f-28xg-22rw | CVE-2026-33895 | node-forge | high | Forge has signature forgery in Ed25519 due to missing S > L check | +| https://github.com/advisories/GHSA-r5fr-rjxr-66jc | CVE-2026-4800 | lodash | high | lodash vulnerable to Code Injection via `_.template` imports key names | +| https://github.com/advisories/GHSA-rf6f-7fwh-wjgh | CVE-2026-33228 | flatted | high | Prototype Pollution via parse() in NodeJS flatted | +| https://github.com/advisories/GHSA-v39h-62p7-jpjc | CVE-2026-6322 | fast-uri | high | fast-uri vulnerable to host confusion via percent-encoded authority delimiters | +| https://github.com/advisories/GHSA-v9p9-hfj2-hcw8 | CVE-2026-2229 | undici | high | Undici has Unhandled Exception in WebSocket Client Due to Invalid server_max_window_bits Validation | +| https://github.com/advisories/GHSA-vrm6-8vpv-qv8q | CVE-2026-1526 | undici | high | Undici has Unbounded Memory Consumption in WebSocket permessage-deflate Decompression | +| https://github.com/advisories/GHSA-vxpw-j846-p89q | CVE-2026-12151 | undici | high | undici WebSocket client vulnerable to denial of service via fragment count bypass | +| https://github.com/advisories/GHSA-w7jw-789q-3m8p | CVE-2026-9277 | shell-quote | critical | shell-quote quote() does not escape newlines in object .op values | +| https://github.com/advisories/GHSA-wf6x-7x77-mvgw | CVE-2026-29063 | immutable | high | Immutable is vulnerable to Prototype Pollution | +| https://github.com/advisories/GHSA-xhpv-hc6g-r9c6 | CVE-2026-33940 | handlebars | high | Handlebars.js has JavaScript Injection via AST Type Confusion when passing an object as dynamic partial | +| https://github.com/advisories/GHSA-xjpj-3mr7-gcpf | CVE-2026-33941 | handlebars | high | Handlebars.js has JavaScript Injection in CLI Precompiler via Unescaped Names and Options | + +### Go Vulnerabilities Fixed + +| ID | CVE/Aliases | Module | Severity | Summary | +| -- | ----------- | ------ | -------- | ------- | +| GO-2024-3333 | CVE-2024-45338, GHSA-w32m-9786-jp63 | golang.org/x/net | N/A | Non-linear parsing of case-insensitive content in golang.org/x/net/html | +| GO-2025-3488 | CVE-2025-22868 | golang.org/x/oauth2 | N/A | Unexpected memory consumption during token parsing in golang.org/x/oauth2 | +| GO-2025-3503 | CVE-2025-22870, GHSA-qxp5-gwg8-xv66 | golang.org/x/net, stdlib | N/A | HTTP Proxy bypass using IPv6 Zone IDs in golang.org/x/net | +| GO-2025-3595 | CVE-2025-22872 | golang.org/x/net | N/A | Incorrect Neutralization of Input During Web Page Generation in x/net in golang.org/x/net | +| GO-2026-4440 | CVE-2025-47911 | golang.org/x/net | N/A | Quadratic parsing complexity in golang.org/x/net/html | +| GO-2026-4441 | CVE-2025-58190 | golang.org/x/net | N/A | Infinite parsing loop in golang.org/x/net | +| GO-2026-4918 | CVE-2026-33814 | golang.org/x/net, stdlib | N/A | Infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE in net/http/internal/http2 in golang.org/x/net | +| GO-2026-5024 | CVE-2026-39824 | golang.org/x/sys | N/A | Invoking integer overflow in NewNTUnicodeString in golang.org/x/sys/windows | +| GO-2026-5025 | CVE-2026-42506 | golang.org/x/net | N/A | Invoking incorrect handling of namespaced elements in foreign content in golang.org/x/net/html | +| GO-2026-5026 | CVE-2026-39821 | golang.org/x/net | N/A | Invoking failure to reject ASCII-only Punycode-encoded labels in golang.org/x/net/idna | +| GO-2026-5027 | CVE-2026-42502 | golang.org/x/net | N/A | Invoking incorrect handling of HTML elements in foreign content in golang.org/x/net/html | +| GO-2026-5028 | CVE-2026-25680 | golang.org/x/net | N/A | Invoking denial of service when parsing arbitrary HTML in golang.org/x/net/html | +| GO-2026-5029 | CVE-2026-25681 | golang.org/x/net | N/A | Invoking incorrect handling of character references in DOCTYPE nodes in golang.org/x/net/html | +| GO-2026-5030 | CVE-2026-27136 | golang.org/x/net | N/A | Invoking duplicate attributes can cause XSS in golang.org/x/net/html | + +## logging-view-plugin (release-coo-ocp-4.15) + +### Commits analyzed + +- `65042b0 Merge pull request #387 from jgbernalp/update-vulnerable-dependencies-4.15-26-06-2026` +- `e726f63 fix: update vulnerable dependencies` +- `352a5e6 Merge pull request #383 from jgbernalp/fix-load-more-and-time-precision-coo-4.15` +- `c1d6289 bugfix: add nanosecond precision to load more calculation to avoid loosing logs on high volume results` +- `dec4cdb refactor: remove unused currentTime` +- `5243694 refactor: add nano seconds unit to variable names, use nanoseconds in all loki client functions` + +### NPM Vulnerabilities Fixed + +| Advisory | CVE | Package | Severity | Title | +| -------- | --- | ------- | -------- | ----- | +| https://github.com/advisories/GHSA-25h7-pfq9-p65f | CVE-2026-32141 | flatted | high | flatted vulnerable to unbounded recursion DoS in parse() revive phase | +| https://github.com/advisories/GHSA-2w6w-674q-4c4q | CVE-2026-33937 | handlebars | critical | Handlebars.js has JavaScript Injection via AST Type Confusion | +| https://github.com/advisories/GHSA-37ch-88jc-xwx2 | CVE-2026-4867 | path-to-regexp | high | path-to-regexp vulnerable to Regular Expression Denial of Service via multiple route parameters | +| https://github.com/advisories/GHSA-3mfm-83xf-c92r | CVE-2026-33938 | handlebars | high | Handlebars.js has JavaScript Injection via AST Type Confusion by tampering @partial-block | +| https://github.com/advisories/GHSA-5c6j-r48x-rmvq | N/A | serialize-javascript | high | Serialize JavaScript is Vulnerable to RCE via RegExp.flags and Date.prototype.toISOString() | +| https://github.com/advisories/GHSA-96hv-2xvq-fx4p | CVE-2026-48779 | ws | high | ws: Memory exhaustion DoS from tiny fragments and data chunks | +| https://github.com/advisories/GHSA-9cx6-37pm-9jff | CVE-2026-33939 | handlebars | high | Handlebars.js has Denial of Service via Malformed Decorator Syntax in Template Compilation | +| https://github.com/advisories/GHSA-c27g-q93r-2cwf | CVE-2024-52011 | launch-editor | high | launch-editor vulnerable to command injection via the crafted request on Windows | +| https://github.com/advisories/GHSA-c2c7-rcm5-vvqj | CVE-2026-33671 | picomatch | high | Picomatch has a ReDoS vulnerability via extglob quantifiers | +| https://github.com/advisories/GHSA-f269-vfmq-vjvj | CVE-2026-1528 | undici | high | Undici: Malicious WebSocket 64-bit length overflows parser and crashes the client | +| https://github.com/advisories/GHSA-fv7c-fp4j-7gwp | CVE-2026-44728 | @babel/plugin-transform-modules-systemjs | high | @babel/plugin-transform-modules-systemjs generates arbitrary code when compiling malicious input | +| https://github.com/advisories/GHSA-hmw2-7cc7-3qxx | CVE-2026-12143 | form-data | high | form-data: CRLF injection in form-data via unescaped multipart field names and filenames | +| https://github.com/advisories/GHSA-ph9p-34f9-6g65 | CVE-2026-44705 | tmp | high | tmp has Path Traversal via unsanitized prefix/postfix that enables directory escape | +| https://github.com/advisories/GHSA-q3j6-qgpj-74h6 | CVE-2026-6321 | fast-uri | high | fast-uri vulnerable to path traversal via percent-encoded dot segments | +| https://github.com/advisories/GHSA-r5fr-rjxr-66jc | CVE-2026-4800 | lodash | high | lodash vulnerable to Code Injection via `_.template` imports key names | +| https://github.com/advisories/GHSA-rf6f-7fwh-wjgh | CVE-2026-33228 | flatted | high | Prototype Pollution via parse() in NodeJS flatted | +| https://github.com/advisories/GHSA-v39h-62p7-jpjc | CVE-2026-6322 | fast-uri | high | fast-uri vulnerable to host confusion via percent-encoded authority delimiters | +| https://github.com/advisories/GHSA-v9p9-hfj2-hcw8 | CVE-2026-2229 | undici | high | Undici has Unhandled Exception in WebSocket Client Due to Invalid server_max_window_bits Validation | +| https://github.com/advisories/GHSA-vrm6-8vpv-qv8q | CVE-2026-1526 | undici | high | Undici has Unbounded Memory Consumption in WebSocket permessage-deflate Decompression | +| https://github.com/advisories/GHSA-vxpw-j846-p89q | CVE-2026-12151 | undici | high | undici WebSocket client vulnerable to denial of service via fragment count bypass | +| https://github.com/advisories/GHSA-w7jw-789q-3m8p | CVE-2026-9277 | shell-quote | critical | shell-quote quote() does not escape newlines in object .op values | +| https://github.com/advisories/GHSA-wf6x-7x77-mvgw | CVE-2026-29063 | immutable | high | Immutable is vulnerable to Prototype Pollution | +| https://github.com/advisories/GHSA-xhpv-hc6g-r9c6 | CVE-2026-33940 | handlebars | high | Handlebars.js has JavaScript Injection via AST Type Confusion when passing an object as dynamic partial | +| https://github.com/advisories/GHSA-xjpj-3mr7-gcpf | CVE-2026-33941 | handlebars | high | Handlebars.js has JavaScript Injection in CLI Precompiler via Unescaped Names and Options | + +### Go Vulnerabilities Fixed + +| ID | CVE/Aliases | Module | Severity | Summary | +| -- | ----------- | ------ | -------- | ------- | +| GO-2025-3488 | CVE-2025-22868 | golang.org/x/oauth2 | N/A | Unexpected memory consumption during token parsing in golang.org/x/oauth2 | +| GO-2025-3503 | CVE-2025-22870, GHSA-qxp5-gwg8-xv66 | golang.org/x/net, stdlib | N/A | HTTP Proxy bypass using IPv6 Zone IDs in golang.org/x/net | +| GO-2025-3595 | CVE-2025-22872 | golang.org/x/net | N/A | Incorrect Neutralization of Input During Web Page Generation in x/net in golang.org/x/net | +| GO-2026-4440 | CVE-2025-47911 | golang.org/x/net | N/A | Quadratic parsing complexity in golang.org/x/net/html | +| GO-2026-4441 | CVE-2025-58190 | golang.org/x/net | N/A | Infinite parsing loop in golang.org/x/net | +| GO-2026-4918 | CVE-2026-33814 | golang.org/x/net, stdlib | N/A | Infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE in net/http/internal/http2 in golang.org/x/net | +| GO-2026-5024 | CVE-2026-39824 | golang.org/x/sys | N/A | Invoking integer overflow in NewNTUnicodeString in golang.org/x/sys/windows | +| GO-2026-5025 | CVE-2026-42506 | golang.org/x/net | N/A | Invoking incorrect handling of namespaced elements in foreign content in golang.org/x/net/html | +| GO-2026-5026 | CVE-2026-39821 | golang.org/x/net | N/A | Invoking failure to reject ASCII-only Punycode-encoded labels in golang.org/x/net/idna | +| GO-2026-5027 | CVE-2026-42502 | golang.org/x/net | N/A | Invoking incorrect handling of HTML elements in foreign content in golang.org/x/net/html | +| GO-2026-5028 | CVE-2026-25680 | golang.org/x/net | N/A | Invoking denial of service when parsing arbitrary HTML in golang.org/x/net/html | +| GO-2026-5029 | CVE-2026-25681 | golang.org/x/net | N/A | Invoking incorrect handling of character references in DOCTYPE nodes in golang.org/x/net/html | +| GO-2026-5030 | CVE-2026-27136 | golang.org/x/net | N/A | Invoking duplicate attributes can cause XSS in golang.org/x/net/html | + +## logging-view-plugin (release-coo-ocp-4.22) + +### Commits analyzed + +- `7edfaf8 Merge pull request #386 from jgbernalp/update-vulnerable-dependencies-4.22-26-06-2026` +- `377462b fix: update vulnerable dependencies` +- `2da80bd Merge pull request #382 from openshift-cherrypick-robot/cherry-pick-381-to-release-coo-ocp-4.22` +- `d24db30 refactor: add nano seconds unit to variable names, use nanoseconds in all loki client functions` +- `233a1ba refactor: remove unused currentTime` +- `71d13ff bugfix: add nanosecond precision to load more calculation to avoid loosing logs on high volume results` + +### NPM Vulnerabilities Fixed + +| Advisory | CVE | Package | Severity | Title | +| -------- | --- | ------- | -------- | ----- | +| https://github.com/advisories/GHSA-96hv-2xvq-fx4p | CVE-2026-48779 | ws | high | ws: Memory exhaustion DoS from tiny fragments and data chunks | +| https://github.com/advisories/GHSA-fv7c-fp4j-7gwp | CVE-2026-44728 | @babel/plugin-transform-modules-systemjs | high | @babel/plugin-transform-modules-systemjs generates arbitrary code when compiling malicious input | +| https://github.com/advisories/GHSA-hm92-r4w5-c3mj | CVE-2026-6734 | undici | high | undici vulnerable to cross-origin request routing via SOCKS5 proxy pool reuse | +| https://github.com/advisories/GHSA-hmw2-7cc7-3qxx | CVE-2026-12143 | form-data | high | form-data: CRLF injection in form-data via unescaped multipart field names and filenames | +| https://github.com/advisories/GHSA-ph9p-34f9-6g65 | CVE-2026-44705 | tmp | high | tmp has Path Traversal via unsanitized prefix/postfix that enables directory escape | +| https://github.com/advisories/GHSA-q3j6-qgpj-74h6 | CVE-2026-6321 | fast-uri | high | fast-uri vulnerable to path traversal via percent-encoded dot segments | +| https://github.com/advisories/GHSA-v39h-62p7-jpjc | CVE-2026-6322 | fast-uri | high | fast-uri vulnerable to host confusion via percent-encoded authority delimiters | +| https://github.com/advisories/GHSA-vmh5-mc38-953g | CVE-2026-9697 | undici | high | undici vulnerable to TLS certificate validation bypass via dropped requestTls in SOCKS5 ProxyAgent | +| https://github.com/advisories/GHSA-vxpw-j846-p89q | CVE-2026-12151 | undici | high | undici WebSocket client vulnerable to denial of service via fragment count bypass | +| https://github.com/advisories/GHSA-w7jw-789q-3m8p | CVE-2026-9277 | shell-quote | critical | shell-quote quote() does not escape newlines in object .op values | + +### Go Vulnerabilities Fixed + +No high/critical Go vulnerabilities were fixed. + +## distributed-tracing-plugin (release-coo-ocp-4.12) + +### Commits analyzed + +- `82b87f6 Merge pull request #289 from openshift/update-vulnerable-dependencies-4.12-26-06-2026` +- `d7ad2f5 fix: update vulnerable dependencies` +- `96ba973 Merge pull request #278 from andreasgerstmayr/backport-more-traces-avail` +- `e7eb82a TRACING-5589: Show a note if there are more traces available` + +### NPM Vulnerabilities Fixed + +| Advisory | CVE | Package | Severity | Title | +| -------- | --- | ------- | -------- | ----- | +| https://github.com/advisories/GHSA-7p7h-4mm5-852v | CVE-2021-33623 | trim-newlines | high | Uncontrolled Resource Consumption in trim-newlines | +| https://github.com/advisories/GHSA-96hv-2xvq-fx4p | CVE-2026-48779 | ws | high | ws: Memory exhaustion DoS from tiny fragments and data chunks | +| https://github.com/advisories/GHSA-fv7c-fp4j-7gwp | CVE-2026-44728 | @babel/plugin-transform-modules-systemjs | high | @babel/plugin-transform-modules-systemjs generates arbitrary code when compiling malicious input | +| https://github.com/advisories/GHSA-grv7-fg5c-xmjg | CVE-2024-4068 | braces | high | Uncontrolled resource consumption in braces | +| https://github.com/advisories/GHSA-hm92-r4w5-c3mj | CVE-2026-6734 | undici | high | undici vulnerable to cross-origin request routing via SOCKS5 proxy pool reuse | +| https://github.com/advisories/GHSA-hmw2-7cc7-3qxx | CVE-2026-12143 | form-data | high | form-data: CRLF injection in form-data via unescaped multipart field names and filenames | +| https://github.com/advisories/GHSA-ph9p-34f9-6g65 | CVE-2026-44705 | tmp | high | tmp has Path Traversal via unsanitized prefix/postfix that enables directory escape | +| https://github.com/advisories/GHSA-q3j6-qgpj-74h6 | CVE-2026-6321 | fast-uri | high | fast-uri vulnerable to path traversal via percent-encoded dot segments | +| https://github.com/advisories/GHSA-v39h-62p7-jpjc | CVE-2026-6322 | fast-uri | high | fast-uri vulnerable to host confusion via percent-encoded authority delimiters | +| https://github.com/advisories/GHSA-vmh5-mc38-953g | CVE-2026-9697 | undici | high | undici vulnerable to TLS certificate validation bypass via dropped requestTls in SOCKS5 ProxyAgent | +| https://github.com/advisories/GHSA-vxpw-j846-p89q | CVE-2026-12151 | undici | high | undici WebSocket client vulnerable to denial of service via fragment count bypass | +| https://github.com/advisories/GHSA-w5p7-h5w8-2hfq | CVE-2020-7753 | trim | high | Regular Expression Denial of Service in trim | +| https://github.com/advisories/GHSA-w7jw-789q-3m8p | CVE-2026-9277 | shell-quote | critical | shell-quote quote() does not escape newlines in object .op values | + +### Go Vulnerabilities Fixed + +| ID | CVE/Aliases | Module | Severity | Summary | +| -- | ----------- | ------ | -------- | ------- | +| GO-2025-3503 | CVE-2025-22870, GHSA-qxp5-gwg8-xv66 | golang.org/x/net, stdlib | N/A | HTTP Proxy bypass using IPv6 Zone IDs in golang.org/x/net | +| GO-2025-3595 | CVE-2025-22872 | golang.org/x/net | N/A | Incorrect Neutralization of Input During Web Page Generation in x/net in golang.org/x/net | +| GO-2026-4440 | CVE-2025-47911 | golang.org/x/net | N/A | Quadratic parsing complexity in golang.org/x/net/html | +| GO-2026-4441 | CVE-2025-58190 | golang.org/x/net | N/A | Infinite parsing loop in golang.org/x/net | +| GO-2026-4918 | CVE-2026-33814 | golang.org/x/net, stdlib | N/A | Infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE in net/http/internal/http2 in golang.org/x/net | +| GO-2026-5024 | CVE-2026-39824 | golang.org/x/sys | N/A | Invoking integer overflow in NewNTUnicodeString in golang.org/x/sys/windows | +| GO-2026-5025 | CVE-2026-42506 | golang.org/x/net | N/A | Invoking incorrect handling of namespaced elements in foreign content in golang.org/x/net/html | +| GO-2026-5026 | CVE-2026-39821 | golang.org/x/net | N/A | Invoking failure to reject ASCII-only Punycode-encoded labels in golang.org/x/net/idna | +| GO-2026-5027 | CVE-2026-42502 | golang.org/x/net | N/A | Invoking incorrect handling of HTML elements in foreign content in golang.org/x/net/html | +| GO-2026-5028 | CVE-2026-25680 | golang.org/x/net | N/A | Invoking denial of service when parsing arbitrary HTML in golang.org/x/net/html | +| GO-2026-5029 | CVE-2026-25681 | golang.org/x/net | N/A | Invoking incorrect handling of character references in DOCTYPE nodes in golang.org/x/net/html | +| GO-2026-5030 | CVE-2026-27136 | golang.org/x/net | N/A | Invoking duplicate attributes can cause XSS in golang.org/x/net/html | + +## distributed-tracing-plugin (release-coo-ocp-4.15) + +### Commits analyzed + +- `a695d12 Merge pull request #288 from openshift/update-vulnerable-dependencies-4.15-26-06-2026` +- `d76d152 fix: update vulnerable dependencies` +- `ee610cc Merge pull request #281 from openshift-cherrypick-robot/cherry-pick-275-to-release-coo-ocp-4.15` +- `c781a14 Fix: Open documentation link in a new browser tab` + +### NPM Vulnerabilities Fixed + +| Advisory | CVE | Package | Severity | Title | +| -------- | --- | ------- | -------- | ----- | +| https://github.com/advisories/GHSA-96hv-2xvq-fx4p | CVE-2026-48779 | ws | high | ws: Memory exhaustion DoS from tiny fragments and data chunks | +| https://github.com/advisories/GHSA-fv7c-fp4j-7gwp | CVE-2026-44728 | @babel/plugin-transform-modules-systemjs | high | @babel/plugin-transform-modules-systemjs generates arbitrary code when compiling malicious input | +| https://github.com/advisories/GHSA-hm92-r4w5-c3mj | CVE-2026-6734 | undici | high | undici vulnerable to cross-origin request routing via SOCKS5 proxy pool reuse | +| https://github.com/advisories/GHSA-hmw2-7cc7-3qxx | CVE-2026-12143 | form-data | high | form-data: CRLF injection in form-data via unescaped multipart field names and filenames | +| https://github.com/advisories/GHSA-ph9p-34f9-6g65 | CVE-2026-44705 | tmp | high | tmp has Path Traversal via unsanitized prefix/postfix that enables directory escape | +| https://github.com/advisories/GHSA-q3j6-qgpj-74h6 | CVE-2026-6321 | fast-uri | high | fast-uri vulnerable to path traversal via percent-encoded dot segments | +| https://github.com/advisories/GHSA-v39h-62p7-jpjc | CVE-2026-6322 | fast-uri | high | fast-uri vulnerable to host confusion via percent-encoded authority delimiters | +| https://github.com/advisories/GHSA-vmh5-mc38-953g | CVE-2026-9697 | undici | high | undici vulnerable to TLS certificate validation bypass via dropped requestTls in SOCKS5 ProxyAgent | +| https://github.com/advisories/GHSA-vxpw-j846-p89q | CVE-2026-12151 | undici | high | undici WebSocket client vulnerable to denial of service via fragment count bypass | +| https://github.com/advisories/GHSA-w7jw-789q-3m8p | CVE-2026-9277 | shell-quote | critical | shell-quote quote() does not escape newlines in object .op values | + +### Go Vulnerabilities Fixed + +| ID | CVE/Aliases | Module | Severity | Summary | +| -- | ----------- | ------ | -------- | ------- | +| GO-2026-4918 | CVE-2026-33814 | golang.org/x/net, stdlib | N/A | Infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE in net/http/internal/http2 in golang.org/x/net | +| GO-2026-5024 | CVE-2026-39824 | golang.org/x/sys | N/A | Invoking integer overflow in NewNTUnicodeString in golang.org/x/sys/windows | +| GO-2026-5025 | CVE-2026-42506 | golang.org/x/net | N/A | Invoking incorrect handling of namespaced elements in foreign content in golang.org/x/net/html | +| GO-2026-5026 | CVE-2026-39821 | golang.org/x/net | N/A | Invoking failure to reject ASCII-only Punycode-encoded labels in golang.org/x/net/idna | +| GO-2026-5027 | CVE-2026-42502 | golang.org/x/net | N/A | Invoking incorrect handling of HTML elements in foreign content in golang.org/x/net/html | +| GO-2026-5028 | CVE-2026-25680 | golang.org/x/net | N/A | Invoking denial of service when parsing arbitrary HTML in golang.org/x/net/html | +| GO-2026-5029 | CVE-2026-25681 | golang.org/x/net | N/A | Invoking incorrect handling of character references in DOCTYPE nodes in golang.org/x/net/html | +| GO-2026-5030 | CVE-2026-27136 | golang.org/x/net | N/A | Invoking duplicate attributes can cause XSS in golang.org/x/net/html | + +## distributed-tracing-plugin (release-coo-ocp-4.19) + +### Commits analyzed + +- `ab35720 Merge pull request #287 from openshift/update-vulnerable-dependencies-4.19-26-06-2026` +- `803ea83 fix: update vulnerable dependencies` +- `5efd64c Merge pull request #280 from openshift-cherrypick-robot/cherry-pick-275-to-release-coo-ocp-4.19` +- `d68e1b9 Fix: Open documentation link in a new browser tab` + +### NPM Vulnerabilities Fixed + +| Advisory | CVE | Package | Severity | Title | +| -------- | --- | ------- | -------- | ----- | +| https://github.com/advisories/GHSA-96hv-2xvq-fx4p | CVE-2026-48779 | ws | high | ws: Memory exhaustion DoS from tiny fragments and data chunks | +| https://github.com/advisories/GHSA-fv7c-fp4j-7gwp | CVE-2026-44728 | @babel/plugin-transform-modules-systemjs | high | @babel/plugin-transform-modules-systemjs generates arbitrary code when compiling malicious input | +| https://github.com/advisories/GHSA-hm92-r4w5-c3mj | CVE-2026-6734 | undici | high | undici vulnerable to cross-origin request routing via SOCKS5 proxy pool reuse | +| https://github.com/advisories/GHSA-hmw2-7cc7-3qxx | CVE-2026-12143 | form-data | high | form-data: CRLF injection in form-data via unescaped multipart field names and filenames | +| https://github.com/advisories/GHSA-ph9p-34f9-6g65 | CVE-2026-44705 | tmp | high | tmp has Path Traversal via unsanitized prefix/postfix that enables directory escape | +| https://github.com/advisories/GHSA-q3j6-qgpj-74h6 | CVE-2026-6321 | fast-uri | high | fast-uri vulnerable to path traversal via percent-encoded dot segments | +| https://github.com/advisories/GHSA-v39h-62p7-jpjc | CVE-2026-6322 | fast-uri | high | fast-uri vulnerable to host confusion via percent-encoded authority delimiters | +| https://github.com/advisories/GHSA-vmh5-mc38-953g | CVE-2026-9697 | undici | high | undici vulnerable to TLS certificate validation bypass via dropped requestTls in SOCKS5 ProxyAgent | +| https://github.com/advisories/GHSA-vxpw-j846-p89q | CVE-2026-12151 | undici | high | undici WebSocket client vulnerable to denial of service via fragment count bypass | +| https://github.com/advisories/GHSA-w7jw-789q-3m8p | CVE-2026-9277 | shell-quote | critical | shell-quote quote() does not escape newlines in object .op values | + +### Go Vulnerabilities Fixed + +| ID | CVE/Aliases | Module | Severity | Summary | +| -- | ----------- | ------ | -------- | ------- | +| GO-2026-4918 | CVE-2026-33814 | golang.org/x/net, stdlib | N/A | Infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE in net/http/internal/http2 in golang.org/x/net | +| GO-2026-5024 | CVE-2026-39824 | golang.org/x/sys | N/A | Invoking integer overflow in NewNTUnicodeString in golang.org/x/sys/windows | +| GO-2026-5025 | CVE-2026-42506 | golang.org/x/net | N/A | Invoking incorrect handling of namespaced elements in foreign content in golang.org/x/net/html | +| GO-2026-5026 | CVE-2026-39821 | golang.org/x/net | N/A | Invoking failure to reject ASCII-only Punycode-encoded labels in golang.org/x/net/idna | +| GO-2026-5027 | CVE-2026-42502 | golang.org/x/net | N/A | Invoking incorrect handling of HTML elements in foreign content in golang.org/x/net/html | +| GO-2026-5028 | CVE-2026-25680 | golang.org/x/net | N/A | Invoking denial of service when parsing arbitrary HTML in golang.org/x/net/html | +| GO-2026-5029 | CVE-2026-25681 | golang.org/x/net | N/A | Invoking incorrect handling of character references in DOCTYPE nodes in golang.org/x/net/html | +| GO-2026-5030 | CVE-2026-27136 | golang.org/x/net | N/A | Invoking duplicate attributes can cause XSS in golang.org/x/net/html | + +## distributed-tracing-plugin (release-coo-ocp-4.22) + +### Commits analyzed + +- `d36dd66 Merge pull request #291 from openshift-cherrypick-robot/cherry-pick-285-to-release-coo-ocp-4.22` +- `5dfcc0c fix: update vulnerable dependencies` +- `a1fec23 Merge pull request #279 from openshift-cherrypick-robot/cherry-pick-275-to-release-coo-ocp-4.22` +- `6ff2f4c Fix: Open documentation link in a new browser tab` + +### NPM Vulnerabilities Fixed + +| Advisory | CVE | Package | Severity | Title | +| -------- | --- | ------- | -------- | ----- | +| https://github.com/advisories/GHSA-96hv-2xvq-fx4p | CVE-2026-48779 | ws | high | ws: Memory exhaustion DoS from tiny fragments and data chunks | +| https://github.com/advisories/GHSA-fv7c-fp4j-7gwp | CVE-2026-44728 | @babel/plugin-transform-modules-systemjs | high | @babel/plugin-transform-modules-systemjs generates arbitrary code when compiling malicious input | +| https://github.com/advisories/GHSA-hm92-r4w5-c3mj | CVE-2026-6734 | undici | high | undici vulnerable to cross-origin request routing via SOCKS5 proxy pool reuse | +| https://github.com/advisories/GHSA-hmw2-7cc7-3qxx | CVE-2026-12143 | form-data | high | form-data: CRLF injection in form-data via unescaped multipart field names and filenames | +| https://github.com/advisories/GHSA-ph9p-34f9-6g65 | CVE-2026-44705 | tmp | high | tmp has Path Traversal via unsanitized prefix/postfix that enables directory escape | +| https://github.com/advisories/GHSA-q3j6-qgpj-74h6 | CVE-2026-6321 | fast-uri | high | fast-uri vulnerable to path traversal via percent-encoded dot segments | +| https://github.com/advisories/GHSA-v39h-62p7-jpjc | CVE-2026-6322 | fast-uri | high | fast-uri vulnerable to host confusion via percent-encoded authority delimiters | +| https://github.com/advisories/GHSA-vmh5-mc38-953g | CVE-2026-9697 | undici | high | undici vulnerable to TLS certificate validation bypass via dropped requestTls in SOCKS5 ProxyAgent | +| https://github.com/advisories/GHSA-vxpw-j846-p89q | CVE-2026-12151 | undici | high | undici WebSocket client vulnerable to denial of service via fragment count bypass | +| https://github.com/advisories/GHSA-w7jw-789q-3m8p | CVE-2026-9277 | shell-quote | critical | shell-quote quote() does not escape newlines in object .op values | + +### Go Vulnerabilities Fixed + +| ID | CVE/Aliases | Module | Severity | Summary | +| -- | ----------- | ------ | -------- | ------- | +| GO-2026-4918 | CVE-2026-33814 | golang.org/x/net, stdlib | N/A | Infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE in net/http/internal/http2 in golang.org/x/net | +| GO-2026-5024 | CVE-2026-39824 | golang.org/x/sys | N/A | Invoking integer overflow in NewNTUnicodeString in golang.org/x/sys/windows | +| GO-2026-5025 | CVE-2026-42506 | golang.org/x/net | N/A | Invoking incorrect handling of namespaced elements in foreign content in golang.org/x/net/html | +| GO-2026-5026 | CVE-2026-39821 | golang.org/x/net | N/A | Invoking failure to reject ASCII-only Punycode-encoded labels in golang.org/x/net/idna | +| GO-2026-5027 | CVE-2026-42502 | golang.org/x/net | N/A | Invoking incorrect handling of HTML elements in foreign content in golang.org/x/net/html | +| GO-2026-5028 | CVE-2026-25680 | golang.org/x/net | N/A | Invoking denial of service when parsing arbitrary HTML in golang.org/x/net/html | +| GO-2026-5029 | CVE-2026-25681 | golang.org/x/net | N/A | Invoking incorrect handling of character references in DOCTYPE nodes in golang.org/x/net/html | +| GO-2026-5030 | CVE-2026-27136 | golang.org/x/net | N/A | Invoking duplicate attributes can cause XSS in golang.org/x/net/html | + +## troubleshooting-panel-plugin (release-coo-ocp-4.19) + +### Commits analyzed + +- `4a04933 Merge pull request #254 from openshift/update-vulnerable-dependencies-4.19-26-06-2026` +- `44bd915 fix: update vulnerable dependencies` +- `83f2504 Merge pull request #233 from openshift-cherrypick-robot/cherry-pick-232-to-release-coo-ocp-4.19` +- `b357576 COO-1819:fix: Add TLS min version and cipher suite configuration support` + +### NPM Vulnerabilities Fixed + +| Advisory | CVE | Package | Severity | Title | +| -------- | --- | ------- | -------- | ----- | +| https://github.com/advisories/GHSA-25h7-pfq9-p65f | CVE-2026-32141 | flatted | high | flatted vulnerable to unbounded recursion DoS in parse() revive phase | +| https://github.com/advisories/GHSA-2w6w-674q-4c4q | CVE-2026-33937 | handlebars | critical | Handlebars.js has JavaScript Injection via AST Type Confusion | +| https://github.com/advisories/GHSA-37ch-88jc-xwx2 | CVE-2026-4867 | path-to-regexp | high | path-to-regexp vulnerable to Regular Expression Denial of Service via multiple route parameters | +| https://github.com/advisories/GHSA-3mfm-83xf-c92r | CVE-2026-33938 | handlebars | high | Handlebars.js has JavaScript Injection via AST Type Confusion by tampering @partial-block | +| https://github.com/advisories/GHSA-96hv-2xvq-fx4p | CVE-2026-48779 | ws | high | ws: Memory exhaustion DoS from tiny fragments and data chunks | +| https://github.com/advisories/GHSA-9cx6-37pm-9jff | CVE-2026-33939 | handlebars | high | Handlebars.js has Denial of Service via Malformed Decorator Syntax in Template Compilation | +| https://github.com/advisories/GHSA-c2c7-rcm5-vvqj | CVE-2026-33671 | picomatch | high | Picomatch has a ReDoS vulnerability via extglob quantifiers | +| https://github.com/advisories/GHSA-f269-vfmq-vjvj | CVE-2026-1528 | undici | high | Undici: Malicious WebSocket 64-bit length overflows parser and crashes the client | +| https://github.com/advisories/GHSA-fv7c-fp4j-7gwp | CVE-2026-44728 | @babel/plugin-transform-modules-systemjs | high | @babel/plugin-transform-modules-systemjs generates arbitrary code when compiling malicious input | +| https://github.com/advisories/GHSA-hmw2-7cc7-3qxx | CVE-2026-12143 | form-data | high | form-data: CRLF injection in form-data via unescaped multipart field names and filenames | +| https://github.com/advisories/GHSA-ph9p-34f9-6g65 | CVE-2026-44705 | tmp | high | tmp has Path Traversal via unsanitized prefix/postfix that enables directory escape | +| https://github.com/advisories/GHSA-q3j6-qgpj-74h6 | CVE-2026-6321 | fast-uri | high | fast-uri vulnerable to path traversal via percent-encoded dot segments | +| https://github.com/advisories/GHSA-r5fr-rjxr-66jc | CVE-2026-4800 | lodash | high | lodash vulnerable to Code Injection via `_.template` imports key names | +| https://github.com/advisories/GHSA-rf6f-7fwh-wjgh | CVE-2026-33228 | flatted | high | Prototype Pollution via parse() in NodeJS flatted | +| https://github.com/advisories/GHSA-v39h-62p7-jpjc | CVE-2026-6322 | fast-uri | high | fast-uri vulnerable to host confusion via percent-encoded authority delimiters | +| https://github.com/advisories/GHSA-v9p9-hfj2-hcw8 | CVE-2026-2229 | undici | high | Undici has Unhandled Exception in WebSocket Client Due to Invalid server_max_window_bits Validation | +| https://github.com/advisories/GHSA-vrm6-8vpv-qv8q | CVE-2026-1526 | undici | high | Undici has Unbounded Memory Consumption in WebSocket permessage-deflate Decompression | +| https://github.com/advisories/GHSA-vxpw-j846-p89q | CVE-2026-12151 | undici | high | undici WebSocket client vulnerable to denial of service via fragment count bypass | +| https://github.com/advisories/GHSA-w7jw-789q-3m8p | CVE-2026-9277 | shell-quote | critical | shell-quote quote() does not escape newlines in object .op values | +| https://github.com/advisories/GHSA-wf6x-7x77-mvgw | CVE-2026-29063 | immutable | high | Immutable is vulnerable to Prototype Pollution | +| https://github.com/advisories/GHSA-xhpv-hc6g-r9c6 | CVE-2026-33940 | handlebars | high | Handlebars.js has JavaScript Injection via AST Type Confusion when passing an object as dynamic partial | +| https://github.com/advisories/GHSA-xjpj-3mr7-gcpf | CVE-2026-33941 | handlebars | high | Handlebars.js has JavaScript Injection in CLI Precompiler via Unescaped Names and Options | + +### Go Vulnerabilities Fixed + +No high/critical Go vulnerabilities were fixed. + +## troubleshooting-panel-plugin (release-coo-ocp-4.22) + +### Commits analyzed + +- `5b562b1 Merge pull request #255 from openshift-cherrypick-robot/cherry-pick-253-to-release-coo-ocp-4.22` +- `958d195 fix: update vulnerable dependencies` +- `94d11ba Merge pull request #247 from openshift-cherrypick-robot/cherry-pick-246-to-release-coo-ocp-4.22` +- `f48f34a fix: COO-1850: Minor UI fixes` + +### NPM Vulnerabilities Fixed + +| Advisory | CVE | Package | Severity | Title | +| -------- | --- | ------- | -------- | ----- | +| https://github.com/advisories/GHSA-96hv-2xvq-fx4p | CVE-2026-48779 | ws | high | ws: Memory exhaustion DoS from tiny fragments and data chunks | +| https://github.com/advisories/GHSA-fv7c-fp4j-7gwp | CVE-2026-44728 | @babel/plugin-transform-modules-systemjs | high | @babel/plugin-transform-modules-systemjs generates arbitrary code when compiling malicious input | +| https://github.com/advisories/GHSA-hm92-r4w5-c3mj | CVE-2026-6734 | undici | high | undici vulnerable to cross-origin request routing via SOCKS5 proxy pool reuse | +| https://github.com/advisories/GHSA-hmw2-7cc7-3qxx | CVE-2026-12143 | form-data | high | form-data: CRLF injection in form-data via unescaped multipart field names and filenames | +| https://github.com/advisories/GHSA-ph9p-34f9-6g65 | CVE-2026-44705 | tmp | high | tmp has Path Traversal via unsanitized prefix/postfix that enables directory escape | +| https://github.com/advisories/GHSA-q3j6-qgpj-74h6 | CVE-2026-6321 | fast-uri | high | fast-uri vulnerable to path traversal via percent-encoded dot segments | +| https://github.com/advisories/GHSA-v39h-62p7-jpjc | CVE-2026-6322 | fast-uri | high | fast-uri vulnerable to host confusion via percent-encoded authority delimiters | +| https://github.com/advisories/GHSA-vmh5-mc38-953g | CVE-2026-9697 | undici | high | undici vulnerable to TLS certificate validation bypass via dropped requestTls in SOCKS5 ProxyAgent | +| https://github.com/advisories/GHSA-vxpw-j846-p89q | CVE-2026-12151 | undici | high | undici WebSocket client vulnerable to denial of service via fragment count bypass | +| https://github.com/advisories/GHSA-w7jw-789q-3m8p | CVE-2026-9277 | shell-quote | critical | shell-quote quote() does not escape newlines in object .op values | + +### Go Vulnerabilities Fixed + +No high/critical Go vulnerabilities were fixed. + +## Summary + +| Project | Branch | NPM Fixed | Go Fixed | Total | Status | +| ------- | ------ | --------- | -------- | ----- | ------ | +| perses-operator | release-coo-1.5 | 0 | 0 | 0 | ok | +| monitoring-plugin | release-coo-ocp-4.15 | 8 | 13 | 21 | ok | +| monitoring-plugin | release-coo-ocp-4.19 | 8 | 13 | 21 | ok | +| monitoring-plugin | release-coo-ocp-4.22 | 11 | 13 | 24 | ok | +| logging-view-plugin | release-coo-ocp-4.12 | 28 | 14 | 42 | ok | +| logging-view-plugin | release-coo-ocp-4.15 | 24 | 13 | 37 | ok | +| logging-view-plugin | release-coo-ocp-4.22 | 10 | 0 | 10 | ok | +| distributed-tracing-plugin | release-coo-ocp-4.12 | 13 | 12 | 25 | ok | +| distributed-tracing-plugin | release-coo-ocp-4.15 | 10 | 8 | 18 | ok | +| distributed-tracing-plugin | release-coo-ocp-4.19 | 10 | 8 | 18 | ok | +| distributed-tracing-plugin | release-coo-ocp-4.22 | 10 | 8 | 18 | ok | +| troubleshooting-panel-plugin | release-coo-ocp-4.19 | 22 | 0 | 22 | ok | +| troubleshooting-panel-plugin | release-coo-ocp-4.22 | 10 | 0 | 10 | ok | + diff --git a/tasks/script-to-extract-fixed-cves/report.yaml b/tasks/script-to-extract-fixed-cves/report.yaml new file mode 100644 index 0000000..c4eb279 --- /dev/null +++ b/tasks/script-to-extract-fixed-cves/report.yaml @@ -0,0 +1,529 @@ +cves: + - key: CVE-2026-48801 + component: monitoring-console-plugin-pf5-1-5 + - key: CVE-2026-48779 + component: monitoring-console-plugin-pf5-1-5 + - key: CVE-2026-6734 + component: monitoring-console-plugin-pf5-1-5 + - key: CVE-2026-12143 + component: monitoring-console-plugin-pf5-1-5 + - key: CVE-2026-44705 + component: monitoring-console-plugin-pf5-1-5 + - key: CVE-2026-9697 + component: monitoring-console-plugin-pf5-1-5 + - key: CVE-2026-12151 + component: monitoring-console-plugin-pf5-1-5 + - key: CVE-2026-9277 + component: monitoring-console-plugin-pf5-1-5 + - key: CVE-2025-22868 + component: monitoring-console-plugin-pf5-1-5 + - key: CVE-2025-22870 + component: monitoring-console-plugin-pf5-1-5 + - key: CVE-2025-22872 + component: monitoring-console-plugin-pf5-1-5 + - key: CVE-2025-47911 + component: monitoring-console-plugin-pf5-1-5 + - key: CVE-2025-58190 + component: monitoring-console-plugin-pf5-1-5 + - key: CVE-2026-33814 + component: monitoring-console-plugin-pf5-1-5 + - key: CVE-2026-39824 + component: monitoring-console-plugin-pf5-1-5 + - key: CVE-2026-42506 + component: monitoring-console-plugin-pf5-1-5 + - key: CVE-2026-39821 + component: monitoring-console-plugin-pf5-1-5 + - key: CVE-2026-42502 + component: monitoring-console-plugin-pf5-1-5 + - key: CVE-2026-25680 + component: monitoring-console-plugin-pf5-1-5 + - key: CVE-2026-25681 + component: monitoring-console-plugin-pf5-1-5 + - key: CVE-2026-27136 + component: monitoring-console-plugin-pf5-1-5 + - key: CVE-2026-48801 + component: monitoring-console-plugin-pf6-1-5 + - key: CVE-2026-48779 + component: monitoring-console-plugin-pf6-1-5 + - key: CVE-2026-6734 + component: monitoring-console-plugin-pf6-1-5 + - key: CVE-2026-12143 + component: monitoring-console-plugin-pf6-1-5 + - key: CVE-2026-44705 + component: monitoring-console-plugin-pf6-1-5 + - key: CVE-2026-9697 + component: monitoring-console-plugin-pf6-1-5 + - key: CVE-2026-12151 + component: monitoring-console-plugin-pf6-1-5 + - key: CVE-2026-9277 + component: monitoring-console-plugin-pf6-1-5 + - key: CVE-2025-22868 + component: monitoring-console-plugin-pf6-1-5 + - key: CVE-2025-22870 + component: monitoring-console-plugin-pf6-1-5 + - key: CVE-2025-22872 + component: monitoring-console-plugin-pf6-1-5 + - key: CVE-2025-47911 + component: monitoring-console-plugin-pf6-1-5 + - key: CVE-2025-58190 + component: monitoring-console-plugin-pf6-1-5 + - key: CVE-2026-33814 + component: monitoring-console-plugin-pf6-1-5 + - key: CVE-2026-39824 + component: monitoring-console-plugin-pf6-1-5 + - key: CVE-2026-42506 + component: monitoring-console-plugin-pf6-1-5 + - key: CVE-2026-39821 + component: monitoring-console-plugin-pf6-1-5 + - key: CVE-2026-42502 + component: monitoring-console-plugin-pf6-1-5 + - key: CVE-2026-25680 + component: monitoring-console-plugin-pf6-1-5 + - key: CVE-2026-25681 + component: monitoring-console-plugin-pf6-1-5 + - key: CVE-2026-27136 + component: monitoring-console-plugin-pf6-1-5 + - key: CVE-2026-48801 + component: monitoring-console-plugin-1-5 + - key: CVE-2026-48779 + component: monitoring-console-plugin-1-5 + - key: CVE-2026-44728 + component: monitoring-console-plugin-1-5 + - key: CVE-2026-6734 + component: monitoring-console-plugin-1-5 + - key: CVE-2026-12143 + component: monitoring-console-plugin-1-5 + - key: CVE-2026-44705 + component: monitoring-console-plugin-1-5 + - key: CVE-2026-6321 + component: monitoring-console-plugin-1-5 + - key: CVE-2026-6322 + component: monitoring-console-plugin-1-5 + - key: CVE-2026-9697 + component: monitoring-console-plugin-1-5 + - key: CVE-2026-12151 + component: monitoring-console-plugin-1-5 + - key: CVE-2026-9277 + component: monitoring-console-plugin-1-5 + - key: CVE-2025-22868 + component: monitoring-console-plugin-1-5 + - key: CVE-2025-22870 + component: monitoring-console-plugin-1-5 + - key: CVE-2025-22872 + component: monitoring-console-plugin-1-5 + - key: CVE-2025-47911 + component: monitoring-console-plugin-1-5 + - key: CVE-2025-58190 + component: monitoring-console-plugin-1-5 + - key: CVE-2026-33814 + component: monitoring-console-plugin-1-5 + - key: CVE-2026-39824 + component: monitoring-console-plugin-1-5 + - key: CVE-2026-42506 + component: monitoring-console-plugin-1-5 + - key: CVE-2026-39821 + component: monitoring-console-plugin-1-5 + - key: CVE-2026-42502 + component: monitoring-console-plugin-1-5 + - key: CVE-2026-25680 + component: monitoring-console-plugin-1-5 + - key: CVE-2026-25681 + component: monitoring-console-plugin-1-5 + - key: CVE-2026-27136 + component: monitoring-console-plugin-1-5 + - key: CVE-2026-33896 + component: logging-console-plugin-pf4-1-5 + - key: CVE-2026-32141 + component: logging-console-plugin-pf4-1-5 + - key: CVE-2026-33937 + component: logging-console-plugin-pf4-1-5 + - key: CVE-2026-4867 + component: logging-console-plugin-pf4-1-5 + - key: CVE-2026-33938 + component: logging-console-plugin-pf4-1-5 + - key: CVE-2026-33891 + component: logging-console-plugin-pf4-1-5 + - key: CVE-2026-48779 + component: logging-console-plugin-pf4-1-5 + - key: CVE-2026-33939 + component: logging-console-plugin-pf4-1-5 + - key: CVE-2024-52011 + component: logging-console-plugin-pf4-1-5 + - key: CVE-2026-33671 + component: logging-console-plugin-pf4-1-5 + - key: CVE-2026-1528 + component: logging-console-plugin-pf4-1-5 + - key: CVE-2026-44728 + component: logging-console-plugin-pf4-1-5 + - key: CVE-2026-12143 + component: logging-console-plugin-pf4-1-5 + - key: CVE-2026-44705 + component: logging-console-plugin-pf4-1-5 + - key: CVE-2026-33894 + component: logging-console-plugin-pf4-1-5 + - key: CVE-2026-6321 + component: logging-console-plugin-pf4-1-5 + - key: CVE-2026-33895 + component: logging-console-plugin-pf4-1-5 + - key: CVE-2026-4800 + component: logging-console-plugin-pf4-1-5 + - key: CVE-2026-33228 + component: logging-console-plugin-pf4-1-5 + - key: CVE-2026-6322 + component: logging-console-plugin-pf4-1-5 + - key: CVE-2026-2229 + component: logging-console-plugin-pf4-1-5 + - key: CVE-2026-1526 + component: logging-console-plugin-pf4-1-5 + - key: CVE-2026-12151 + component: logging-console-plugin-pf4-1-5 + - key: CVE-2026-9277 + component: logging-console-plugin-pf4-1-5 + - key: CVE-2026-29063 + component: logging-console-plugin-pf4-1-5 + - key: CVE-2026-33940 + component: logging-console-plugin-pf4-1-5 + - key: CVE-2026-33941 + component: logging-console-plugin-pf4-1-5 + - key: CVE-2024-45338 + component: logging-console-plugin-pf4-1-5 + - key: CVE-2025-22868 + component: logging-console-plugin-pf4-1-5 + - key: CVE-2025-22870 + component: logging-console-plugin-pf4-1-5 + - key: CVE-2025-22872 + component: logging-console-plugin-pf4-1-5 + - key: CVE-2025-47911 + component: logging-console-plugin-pf4-1-5 + - key: CVE-2025-58190 + component: logging-console-plugin-pf4-1-5 + - key: CVE-2026-33814 + component: logging-console-plugin-pf4-1-5 + - key: CVE-2026-39824 + component: logging-console-plugin-pf4-1-5 + - key: CVE-2026-42506 + component: logging-console-plugin-pf4-1-5 + - key: CVE-2026-39821 + component: logging-console-plugin-pf4-1-5 + - key: CVE-2026-42502 + component: logging-console-plugin-pf4-1-5 + - key: CVE-2026-25680 + component: logging-console-plugin-pf4-1-5 + - key: CVE-2026-25681 + component: logging-console-plugin-pf4-1-5 + - key: CVE-2026-27136 + component: logging-console-plugin-pf4-1-5 + - key: CVE-2026-32141 + component: logging-console-plugin-pf5-1-5 + - key: CVE-2026-33937 + component: logging-console-plugin-pf5-1-5 + - key: CVE-2026-4867 + component: logging-console-plugin-pf5-1-5 + - key: CVE-2026-33938 + component: logging-console-plugin-pf5-1-5 + - key: CVE-2026-48779 + component: logging-console-plugin-pf5-1-5 + - key: CVE-2026-33939 + component: logging-console-plugin-pf5-1-5 + - key: CVE-2024-52011 + component: logging-console-plugin-pf5-1-5 + - key: CVE-2026-33671 + component: logging-console-plugin-pf5-1-5 + - key: CVE-2026-1528 + component: logging-console-plugin-pf5-1-5 + - key: CVE-2026-44728 + component: logging-console-plugin-pf5-1-5 + - key: CVE-2026-12143 + component: logging-console-plugin-pf5-1-5 + - key: CVE-2026-44705 + component: logging-console-plugin-pf5-1-5 + - key: CVE-2026-6321 + component: logging-console-plugin-pf5-1-5 + - key: CVE-2026-4800 + component: logging-console-plugin-pf5-1-5 + - key: CVE-2026-33228 + component: logging-console-plugin-pf5-1-5 + - key: CVE-2026-6322 + component: logging-console-plugin-pf5-1-5 + - key: CVE-2026-2229 + component: logging-console-plugin-pf5-1-5 + - key: CVE-2026-1526 + component: logging-console-plugin-pf5-1-5 + - key: CVE-2026-12151 + component: logging-console-plugin-pf5-1-5 + - key: CVE-2026-9277 + component: logging-console-plugin-pf5-1-5 + - key: CVE-2026-29063 + component: logging-console-plugin-pf5-1-5 + - key: CVE-2026-33940 + component: logging-console-plugin-pf5-1-5 + - key: CVE-2026-33941 + component: logging-console-plugin-pf5-1-5 + - key: CVE-2025-22868 + component: logging-console-plugin-pf5-1-5 + - key: CVE-2025-22870 + component: logging-console-plugin-pf5-1-5 + - key: CVE-2025-22872 + component: logging-console-plugin-pf5-1-5 + - key: CVE-2025-47911 + component: logging-console-plugin-pf5-1-5 + - key: CVE-2025-58190 + component: logging-console-plugin-pf5-1-5 + - key: CVE-2026-33814 + component: logging-console-plugin-pf5-1-5 + - key: CVE-2026-39824 + component: logging-console-plugin-pf5-1-5 + - key: CVE-2026-42506 + component: logging-console-plugin-pf5-1-5 + - key: CVE-2026-39821 + component: logging-console-plugin-pf5-1-5 + - key: CVE-2026-42502 + component: logging-console-plugin-pf5-1-5 + - key: CVE-2026-25680 + component: logging-console-plugin-pf5-1-5 + - key: CVE-2026-25681 + component: logging-console-plugin-pf5-1-5 + - key: CVE-2026-27136 + component: logging-console-plugin-pf5-1-5 + - key: CVE-2026-48779 + component: logging-console-plugin-1-5 + - key: CVE-2026-44728 + component: logging-console-plugin-1-5 + - key: CVE-2026-6734 + component: logging-console-plugin-1-5 + - key: CVE-2026-12143 + component: logging-console-plugin-1-5 + - key: CVE-2026-44705 + component: logging-console-plugin-1-5 + - key: CVE-2026-6321 + component: logging-console-plugin-1-5 + - key: CVE-2026-6322 + component: logging-console-plugin-1-5 + - key: CVE-2026-9697 + component: logging-console-plugin-1-5 + - key: CVE-2026-12151 + component: logging-console-plugin-1-5 + - key: CVE-2026-9277 + component: logging-console-plugin-1-5 + - key: CVE-2021-33623 + component: distributed-tracing-console-plugin-pf4-1-5 + - key: CVE-2026-48779 + component: distributed-tracing-console-plugin-pf4-1-5 + - key: CVE-2026-44728 + component: distributed-tracing-console-plugin-pf4-1-5 + - key: CVE-2024-4068 + component: distributed-tracing-console-plugin-pf4-1-5 + - key: CVE-2026-6734 + component: distributed-tracing-console-plugin-pf4-1-5 + - key: CVE-2026-12143 + component: distributed-tracing-console-plugin-pf4-1-5 + - key: CVE-2026-44705 + component: distributed-tracing-console-plugin-pf4-1-5 + - key: CVE-2026-6321 + component: distributed-tracing-console-plugin-pf4-1-5 + - key: CVE-2026-6322 + component: distributed-tracing-console-plugin-pf4-1-5 + - key: CVE-2026-9697 + component: distributed-tracing-console-plugin-pf4-1-5 + - key: CVE-2026-12151 + component: distributed-tracing-console-plugin-pf4-1-5 + - key: CVE-2020-7753 + component: distributed-tracing-console-plugin-pf4-1-5 + - key: CVE-2026-9277 + component: distributed-tracing-console-plugin-pf4-1-5 + - key: CVE-2025-22870 + component: distributed-tracing-console-plugin-pf4-1-5 + - key: CVE-2025-22872 + component: distributed-tracing-console-plugin-pf4-1-5 + - key: CVE-2025-47911 + component: distributed-tracing-console-plugin-pf4-1-5 + - key: CVE-2025-58190 + component: distributed-tracing-console-plugin-pf4-1-5 + - key: CVE-2026-33814 + component: distributed-tracing-console-plugin-pf4-1-5 + - key: CVE-2026-39824 + component: distributed-tracing-console-plugin-pf4-1-5 + - key: CVE-2026-42506 + component: distributed-tracing-console-plugin-pf4-1-5 + - key: CVE-2026-39821 + component: distributed-tracing-console-plugin-pf4-1-5 + - key: CVE-2026-42502 + component: distributed-tracing-console-plugin-pf4-1-5 + - key: CVE-2026-25680 + component: distributed-tracing-console-plugin-pf4-1-5 + - key: CVE-2026-25681 + component: distributed-tracing-console-plugin-pf4-1-5 + - key: CVE-2026-27136 + component: distributed-tracing-console-plugin-pf4-1-5 + - key: CVE-2026-48779 + component: distributed-tracing-console-plugin-pf5-1-5 + - key: CVE-2026-44728 + component: distributed-tracing-console-plugin-pf5-1-5 + - key: CVE-2026-6734 + component: distributed-tracing-console-plugin-pf5-1-5 + - key: CVE-2026-12143 + component: distributed-tracing-console-plugin-pf5-1-5 + - key: CVE-2026-44705 + component: distributed-tracing-console-plugin-pf5-1-5 + - key: CVE-2026-6321 + component: distributed-tracing-console-plugin-pf5-1-5 + - key: CVE-2026-6322 + component: distributed-tracing-console-plugin-pf5-1-5 + - key: CVE-2026-9697 + component: distributed-tracing-console-plugin-pf5-1-5 + - key: CVE-2026-12151 + component: distributed-tracing-console-plugin-pf5-1-5 + - key: CVE-2026-9277 + component: distributed-tracing-console-plugin-pf5-1-5 + - key: CVE-2026-33814 + component: distributed-tracing-console-plugin-pf5-1-5 + - key: CVE-2026-39824 + component: distributed-tracing-console-plugin-pf5-1-5 + - key: CVE-2026-42506 + component: distributed-tracing-console-plugin-pf5-1-5 + - key: CVE-2026-39821 + component: distributed-tracing-console-plugin-pf5-1-5 + - key: CVE-2026-42502 + component: distributed-tracing-console-plugin-pf5-1-5 + - key: CVE-2026-25680 + component: distributed-tracing-console-plugin-pf5-1-5 + - key: CVE-2026-25681 + component: distributed-tracing-console-plugin-pf5-1-5 + - key: CVE-2026-27136 + component: distributed-tracing-console-plugin-pf5-1-5 + - key: CVE-2026-48779 + component: distributed-tracing-console-plugin-pf6-1-5 + - key: CVE-2026-44728 + component: distributed-tracing-console-plugin-pf6-1-5 + - key: CVE-2026-6734 + component: distributed-tracing-console-plugin-pf6-1-5 + - key: CVE-2026-12143 + component: distributed-tracing-console-plugin-pf6-1-5 + - key: CVE-2026-44705 + component: distributed-tracing-console-plugin-pf6-1-5 + - key: CVE-2026-6321 + component: distributed-tracing-console-plugin-pf6-1-5 + - key: CVE-2026-6322 + component: distributed-tracing-console-plugin-pf6-1-5 + - key: CVE-2026-9697 + component: distributed-tracing-console-plugin-pf6-1-5 + - key: CVE-2026-12151 + component: distributed-tracing-console-plugin-pf6-1-5 + - key: CVE-2026-9277 + component: distributed-tracing-console-plugin-pf6-1-5 + - key: CVE-2026-33814 + component: distributed-tracing-console-plugin-pf6-1-5 + - key: CVE-2026-39824 + component: distributed-tracing-console-plugin-pf6-1-5 + - key: CVE-2026-42506 + component: distributed-tracing-console-plugin-pf6-1-5 + - key: CVE-2026-39821 + component: distributed-tracing-console-plugin-pf6-1-5 + - key: CVE-2026-42502 + component: distributed-tracing-console-plugin-pf6-1-5 + - key: CVE-2026-25680 + component: distributed-tracing-console-plugin-pf6-1-5 + - key: CVE-2026-25681 + component: distributed-tracing-console-plugin-pf6-1-5 + - key: CVE-2026-27136 + component: distributed-tracing-console-plugin-pf6-1-5 + - key: CVE-2026-48779 + component: distributed-tracing-console-plugin-1-5 + - key: CVE-2026-44728 + component: distributed-tracing-console-plugin-1-5 + - key: CVE-2026-6734 + component: distributed-tracing-console-plugin-1-5 + - key: CVE-2026-12143 + component: distributed-tracing-console-plugin-1-5 + - key: CVE-2026-44705 + component: distributed-tracing-console-plugin-1-5 + - key: CVE-2026-6321 + component: distributed-tracing-console-plugin-1-5 + - key: CVE-2026-6322 + component: distributed-tracing-console-plugin-1-5 + - key: CVE-2026-9697 + component: distributed-tracing-console-plugin-1-5 + - key: CVE-2026-12151 + component: distributed-tracing-console-plugin-1-5 + - key: CVE-2026-9277 + component: distributed-tracing-console-plugin-1-5 + - key: CVE-2026-33814 + component: distributed-tracing-console-plugin-1-5 + - key: CVE-2026-39824 + component: distributed-tracing-console-plugin-1-5 + - key: CVE-2026-42506 + component: distributed-tracing-console-plugin-1-5 + - key: CVE-2026-39821 + component: distributed-tracing-console-plugin-1-5 + - key: CVE-2026-42502 + component: distributed-tracing-console-plugin-1-5 + - key: CVE-2026-25680 + component: distributed-tracing-console-plugin-1-5 + - key: CVE-2026-25681 + component: distributed-tracing-console-plugin-1-5 + - key: CVE-2026-27136 + component: distributed-tracing-console-plugin-1-5 + - key: CVE-2026-32141 + component: troubleshooting-panel-console-plugin-pf6-1-5 + - key: CVE-2026-33937 + component: troubleshooting-panel-console-plugin-pf6-1-5 + - key: CVE-2026-4867 + component: troubleshooting-panel-console-plugin-pf6-1-5 + - key: CVE-2026-33938 + component: troubleshooting-panel-console-plugin-pf6-1-5 + - key: CVE-2026-48779 + component: troubleshooting-panel-console-plugin-pf6-1-5 + - key: CVE-2026-33939 + component: troubleshooting-panel-console-plugin-pf6-1-5 + - key: CVE-2026-33671 + component: troubleshooting-panel-console-plugin-pf6-1-5 + - key: CVE-2026-1528 + component: troubleshooting-panel-console-plugin-pf6-1-5 + - key: CVE-2026-44728 + component: troubleshooting-panel-console-plugin-pf6-1-5 + - key: CVE-2026-12143 + component: troubleshooting-panel-console-plugin-pf6-1-5 + - key: CVE-2026-44705 + component: troubleshooting-panel-console-plugin-pf6-1-5 + - key: CVE-2026-6321 + component: troubleshooting-panel-console-plugin-pf6-1-5 + - key: CVE-2026-4800 + component: troubleshooting-panel-console-plugin-pf6-1-5 + - key: CVE-2026-33228 + component: troubleshooting-panel-console-plugin-pf6-1-5 + - key: CVE-2026-6322 + component: troubleshooting-panel-console-plugin-pf6-1-5 + - key: CVE-2026-2229 + component: troubleshooting-panel-console-plugin-pf6-1-5 + - key: CVE-2026-1526 + component: troubleshooting-panel-console-plugin-pf6-1-5 + - key: CVE-2026-12151 + component: troubleshooting-panel-console-plugin-pf6-1-5 + - key: CVE-2026-9277 + component: troubleshooting-panel-console-plugin-pf6-1-5 + - key: CVE-2026-29063 + component: troubleshooting-panel-console-plugin-pf6-1-5 + - key: CVE-2026-33940 + component: troubleshooting-panel-console-plugin-pf6-1-5 + - key: CVE-2026-33941 + component: troubleshooting-panel-console-plugin-pf6-1-5 + - key: CVE-2026-48779 + component: troubleshooting-panel-console-plugin-1-5 + - key: CVE-2026-44728 + component: troubleshooting-panel-console-plugin-1-5 + - key: CVE-2026-6734 + component: troubleshooting-panel-console-plugin-1-5 + - key: CVE-2026-12143 + component: troubleshooting-panel-console-plugin-1-5 + - key: CVE-2026-44705 + component: troubleshooting-panel-console-plugin-1-5 + - key: CVE-2026-6321 + component: troubleshooting-panel-console-plugin-1-5 + - key: CVE-2026-6322 + component: troubleshooting-panel-console-plugin-1-5 + - key: CVE-2026-9697 + component: troubleshooting-panel-console-plugin-1-5 + - key: CVE-2026-12151 + component: troubleshooting-panel-console-plugin-1-5 + - key: CVE-2026-9277 + component: troubleshooting-panel-console-plugin-1-5 diff --git a/tasks/script-to-extract-fixed-cves/spec.md b/tasks/script-to-extract-fixed-cves/spec.md new file mode 100644 index 0000000..45788ff --- /dev/null +++ b/tasks/script-to-extract-fixed-cves/spec.md @@ -0,0 +1,30 @@ +# Spec: Script to extract fixed CVEs + +## Related projects and branches + +- perses-operator: release-coo-1.5 +- monitoring-plugin: release-coo-ocp-4.15 +- monitoring-plugin: release-coo-ocp-4.19 +- monitoring-plugin: release-coo-ocp-4.22 +- logging-view-plugin: release-coo-ocp-4.12 +- logging-view-plugin: release-coo-ocp-4.15 +- logging-view-plugin: release-coo-ocp-4.22 +- distributed-tracing-console-plugin: release-coo-ocp-4.12 +- distributed-tracing-console-plugin: release-coo-ocp-4.15 +- distributed-tracing-console-plugin: release-coo-ocp-4.19 +- distributed-tracing-console-plugin: release-coo-ocp-4.22 +- troubleshooting-panel-console-plugin: release-coo-ocp-4.19 +- troubleshooting-panel-console-plugin: release-coo-ocp-4.22 + +## Description + +I need to create a script that extracts the fixed CVEs from the latest commits. The script should rollback the last 3 commits and execute the +`npm audit` command to get the list of fixed CVEs. In some projects the frontend could be installed in a different directory, so the script should be +able to handle that. It should also detect the vulnerabilities that were fixed in go using govulncheck. The script should be able to handle different +package managers and should be able to extract the fixed CVEs from the output of both analysis tools + +## Acceptance criteria + +- The script should be able to rollback the last 3 commits and execute the `npm audit` command to get the list of fixed CVEs. +- The script should be able to rollback the last 3 commits and execute the `govulncheck` command to get the list of fixed CVEs. +- The list should be able to receive multiple projects in a loop.