Skip to content

feat(vulnfeeds): add repository-level GHSA advisory converter - #6065

Draft
another-rex wants to merge 2 commits into
google:masterfrom
another-rex:ghsa_repo_osv_tool
Draft

another-rex wants to merge 2 commits into
google:masterfrom
another-rex:ghsa_repo_osv_tool

Conversation

@another-rex

Copy link
Copy Markdown
Contributor

This PR introduces the repository-ghsa vulnerability feed converter tool under vulnfeeds/cmd/converters/repository-ghsa/ to fetch and convert repository-level GitHub Security Advisories (GHSAs) into the OSV Git repository advisory schema.

Summary of Changes

  • Tool Implementation (vulnfeeds/cmd/converters/repository-ghsa):
    • github.go: GitHub REST API client with Bearer token authentication, cursor pagination via Link header, and exponential backoff retry on HTTP 429/5xx.
    • convert.go: Converts GHSA advisories to OSV records. Produces pure Git records (omitting package and ecosystem), resolves version ranges against Git tags via Gitter / Git tags cache into commit SHAs (Range_GIT), and records original GHSA version bounds in database_specific.extracted_events.
    • main.go: CLI tool orchestrating repository ingestion across worker goroutines. Supports reading repository lists from local files or GCS (gs://..., JSON arrays/dicts/lists), writing output to local directories or GCS buckets, and recording execution timestamps in Datastore.
    • jobdata.go: Datastore JobData entity tracking (repository_ghsa_last_run) for recording job execution timestamps.
  • Deployment & Automation:
    • Dockerfile & run_repository_ghsa.sh: Multi-stage container build and entrypoint script for running the converter in containerized environments.
    • deployment/build-and-stage.yaml: Cloud Build pipeline steps to build, tag, and push gcr.io/oss-vdb/repository-ghsa-convert.
    • Kubernetes CronJobs (deployment/clouddeploy/gke-workers/): Scheduled every 6 hours (0 */6 * * *) in base feeds with environment overlays for oss-vdb-test (test bucket) and oss-vdb (prod bucket).
  • Tests:
    • Comprehensive unit and integration test coverage across github_test.go, convert_test.go, jobdata_test.go, and main_test.go with 100% pass rate and zero race conditions (-race).
    • Validated with poetry run ./tools/lint_and_format.sh.

agy

…nverter

- Support reading repository targets from GCS JSON/manifest files (gs://...).
- Support directly uploading converted OSV records to GCS bucket.
- Save execution timestamps to Datastore JobData entity (repository_ghsa_last_run).
- Add Kubernetes CronJob manifests running every 6 hours (0 */6 * * *) for base, oss-vdb-test, and oss-vdb environments.
- Add Dockerfile and Cloud Build step for building and staging the converter container.
- Completely omit package and ecosystem fields for pure Git advisories.
- Store original GHSA version bounds in range.database_specific.extracted_events.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant