advisory-scan: NVD by CPE, so mattermost and mumble stop scanning as '?' #11
@@ -109,9 +109,18 @@ CRITICAL came from, and an image with no window is not counted at all.
|
||||
python3 cc-ci-plan/audit-sources.py --security-sources
|
||||
```
|
||||
A recipe whose sources yield **no CVE data at all** cannot produce a meaningful `0` — nothing was
|
||||
measured, the same way a missing registry file cannot. As of 2026-08-11 that is **mattermost-lts**
|
||||
(its GitHub advisory feed is empty and its security bulletins are client-side rendered) and
|
||||
**mumble**. Render those as **`?`**, not `0`, and say why in the notes.
|
||||
measured, the same way a missing registry file cannot. Render those as **`?`**, not `0`.
|
||||
|
||||
**The fleet is currently at zero such recipes.** The last two — `mattermost-lts` (empty advisory
|
||||
feed, client-side-rendered bulletins) and `mumble` (nothing published anywhere) — were fixed by
|
||||
declaring an NVD CPE in their registry:
|
||||
```
|
||||
- nvd-cpe: mattermost-team-edition = cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:*
|
||||
```
|
||||
**If this sweep ever reports a blind recipe again, that is the fix**: find the product's CPE at
|
||||
nvd.nist.gov and add the line. Prefer a real advisory feed or an attributable changelog when one
|
||||
exists — NVD lags the vendor — but a lagging source beats no source, and it turns a `?` into a
|
||||
number.
|
||||
|
||||
An *unparseable page* is NOT the same thing: it is harmless when the same project also publishes an
|
||||
advisory feed (redis, gitea, minio, clickhouse all do). Only "no usable source for this image" counts.
|
||||
|
||||
Reference in New Issue
Block a user