Skip to content

fix(parser): keep every affected component of a CVE, not just the first - #71

Merged
dmchaledev merged 2 commits into
mainfrom
fix/cve-blast-radius
Aug 7, 2026
Merged

fix(parser): keep every affected component of a CVE, not just the first#71
dmchaledev merged 2 commits into
mainfrom
fix/cve-blast-radius

Conversation

@dmchaledev

Copy link
Copy Markdown
Contributor

Closes #30

Problem

extractCycloneDXAffects read affects[0].ref and discarded the rest, so a CVE hitting multiple packages (Log4Shell → log4j-core + log4j-api) was reported with a truncated blast radius.

Fix

  • CVEEntry.affects is now string[]; the parser collects every ref
  • Reporter joins them via joinAffects (text/markdown/JSON)

Verification

  • New test: Log4Shell keeps both affected purls
  • 113 tests pass, tsc clean

Hermes Agent added 2 commits August 7, 2026 13:36
…ing them

Closes #50

buildComponentMap used last-write-wins on the purl/name key: when one SBOM
contained two components with the same key (purl-less same-name packages in
OS/container SBOMs, distinct purls collapsing to one coordinate), every entry
but the last vanished before the diff ran — so added/removed packages could
disappear from the report entirely.

- Every component now gets a unique key: first occurrence keeps the bare key,
  collisions get a #2/#3 suffix. All entries survive into the diff.
- Deterministic: stable input order yields stable keys.
- 2 new tests: same-key removal is reported; same-key pairs match by
  occurrence order (upgrade, not add+remove).

112 tests pass, tsc clean.
Closes #30

extractCycloneDXAffects read affects[0].ref and discarded the rest, so a
CVE hitting multiple packages (Log4Shell → log4j-core + log4j-api) was
reported with a truncated blast radius.

- CVEEntry.affects is now string[]; parser collects every ref
- Reporter joins them (text/markdown/JSON) via joinAffects
- New test: Log4Shell keeps both affected purls

113 tests pass, tsc clean.
@dmchaledev
dmchaledev merged commit 7e7a084 into main Aug 7, 2026
2 checks passed
@dmchaledev
dmchaledev deleted the fix/cve-blast-radius branch August 7, 2026 19:41
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

CVE blast radius is truncated: parser keeps only the first affected component (affects[0]), hiding every other package a CVE hits

1 participant