audit-sources --security-sources: find the recipes that cannot see CVEs at all
Follow-up to the nginx blind spot. Sweeping all 22 recipes for sources whose CVEs are USABLE (structured advisory feed, or a changelog attributable to releases) rather than merely visible. Before the changelog-attribution fix: 20 unusable sources. After: 5, and all five are redundant - the same project also publishes an advisory feed (redis, gitea, minio, clickhouse), so nothing is actually lost. One real find, same shape as nginx: ONLYOFFICE/DocumentServer publishes NO GitHub advisories, and the registry pointed its CHANGELOG.md at the GitHub *blob* page - 636KB of markup in which the release headings do not survive HTML-stripping, so 24 CVEs were visible and NONE attributable. The raw URL attributes all 24. Rather than fix one registry line, advisory-scan now normalises github.com/../blob/.. to raw.githubusercontent.com, which fixes every entry present and future. lasuite-drive bumps documentserver, so this was live. Genuinely blind after all that: mattermost-lts and mumble - no advisory feed, no attributable changelog, no CVE data anywhere the registry points. mattermost is the notable one: its bulletins are client-side rendered, so a regex sweep sees nothing. Their scans can report 0 while nothing was measured, so /cve-check now renders those recipes as ? and says why. The audit output distinguishes a blind RECIPE from an unparseable PAGE, because conflating them made 5 harmless redundancies look like 5 gaps.
This commit is contained in:
@@ -104,6 +104,18 @@ CRITICAL came from, and an image with no window is not counted at all.
|
||||
distinction was the difference between two false zeros and the truth (both recipes turned out fine,
|
||||
but nothing in the survey said so).
|
||||
|
||||
### 2c. Know which recipes CANNOT see CVEs at all
|
||||
```
|
||||
python3 cc-ci-plan/audit-sources.py --security-sources
|
||||
```
|
||||
A recipe whose sources yield **no CVE data at all** cannot produce a meaningful `0` — nothing was
|
||||
measured, the same way a missing registry file cannot. As of 2026-08-11 that is **mattermost-lts**
|
||||
(its GitHub advisory feed is empty and its security bulletins are client-side rendered) and
|
||||
**mumble**. Render those as **`?`**, not `0`, and say why in the notes.
|
||||
|
||||
An *unparseable page* is NOT the same thing: it is harmless when the same project also publishes an
|
||||
advisory feed (redis, gitea, minio, clickhouse all do). Only "no usable source for this image" counts.
|
||||
|
||||
### 3. Run the advisory scan over that window
|
||||
```
|
||||
python3 /srv/cc-ci/cc-ci-plan/advisory-scan.py <recipe> --from <old-app> --to <new-app> \
|
||||
|
||||
Reference in New Issue
Block a user