fix(parser): keep every affected component of a CVE, not just the first - #71
Merged
Conversation
added 2 commits
August 7, 2026 13:36
…ing them Closes #50 buildComponentMap used last-write-wins on the purl/name key: when one SBOM contained two components with the same key (purl-less same-name packages in OS/container SBOMs, distinct purls collapsing to one coordinate), every entry but the last vanished before the diff ran — so added/removed packages could disappear from the report entirely. - Every component now gets a unique key: first occurrence keeps the bare key, collisions get a #2/#3 suffix. All entries survive into the diff. - Deterministic: stable input order yields stable keys. - 2 new tests: same-key removal is reported; same-key pairs match by occurrence order (upgrade, not add+remove). 112 tests pass, tsc clean.
Closes #30 extractCycloneDXAffects read affects[0].ref and discarded the rest, so a CVE hitting multiple packages (Log4Shell → log4j-core + log4j-api) was reported with a truncated blast radius. - CVEEntry.affects is now string[]; parser collects every ref - Reporter joins them (text/markdown/JSON) via joinAffects - New test: Log4Shell keeps both affected purls 113 tests pass, tsc clean.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Closes #30
Problem
extractCycloneDXAffects read affects[0].ref and discarded the rest, so a CVE hitting multiple packages (Log4Shell → log4j-core + log4j-api) was reported with a truncated blast radius.
Fix
Verification