|
| 1 | +# |
| 2 | +# Copyright (c) nexB Inc. and others. All rights reserved. |
| 3 | +# VulnerableCode is a trademark of nexB Inc. |
| 4 | +# SPDX-License-Identifier: Apache-2.0 |
| 5 | +# See http://www.apache.org/licenses/LICENSE-2.0 for the license text. |
| 6 | +# See https://github.com/aboutcode-org/vulnerablecode for support or download. |
| 7 | +# See https://aboutcode.org for more information about nexB OSS projects. |
| 8 | +# |
| 9 | + |
| 10 | +import json |
| 11 | +import logging |
| 12 | +import traceback |
| 13 | + |
| 14 | +import pytz |
| 15 | +from dateutil import parser as dateparser |
| 16 | +from univers.version_range import RANGE_CLASS_BY_SCHEMES |
| 17 | +from univers.version_range import from_gitlab_native |
| 18 | + |
| 19 | +from vulnerabilities.importer import AdvisoryData |
| 20 | +from vulnerabilities.importer import AffectedPackageV2 |
| 21 | +from vulnerabilities.importer import ReferenceV2 |
| 22 | +from vulnerabilities.utils import build_description |
| 23 | +from vulnerabilities.utils import get_cwe_id |
| 24 | + |
| 25 | + |
| 26 | +def advisory_dict_to_advisory_data( |
| 27 | + advisory: dict, |
| 28 | + *, |
| 29 | + purl_type_by_gitlab_scheme, |
| 30 | + gitlab_scheme_by_purl_type, |
| 31 | + logger, |
| 32 | + get_purl_fn, |
| 33 | + purl=None, |
| 34 | + advisory_url=None, |
| 35 | +): |
| 36 | + """ |
| 37 | + Convert a GitLab advisory mapping (already loaded from YAML or JSON) to an |
| 38 | + `AdvisoryData` instance. |
| 39 | + Returns None when no affected or fixed version range can be derived. |
| 40 | +
|
| 41 | + Parameters: |
| 42 | + - advisory: dict per GitLab schema (identifier, package_slug, ...) |
| 43 | + - purl_type_by_gitlab_scheme: mapping of GitLab package type to PackageURL type |
| 44 | + - gitlab_scheme_by_purl_type: inverse mapping of PackageURL type to GitLab type |
| 45 | + - logger: callable like pipeline.log(message, level=logging.LEVEL) |
| 46 | + - get_purl_fn: function to build a version-less PURL from package_slug |
| 47 | + - purl: optional PURL (may include version); used only for context, ranges use |
| 48 | + a version-less PURL derived from package_slug via get_purl_fn |
| 49 | + - advisory_url: optional URL; if not provided, a default URL will be built when possible |
| 50 | + """ |
| 51 | + |
| 52 | + aliases = list(advisory.get("identifiers", []) or []) |
| 53 | + identifier = advisory.get("identifier") or "" |
| 54 | + package_slug = advisory.get("package_slug") |
| 55 | + |
| 56 | + advisory_id = f"{package_slug}/{identifier}" if package_slug else identifier |
| 57 | + if advisory_id in aliases: |
| 58 | + try: |
| 59 | + aliases.remove(advisory_id) |
| 60 | + except ValueError: |
| 61 | + pass |
| 62 | + |
| 63 | + summary = build_description(advisory.get("title"), advisory.get("description")) |
| 64 | + urls = advisory.get("urls") or [] |
| 65 | + references = [ReferenceV2.from_url(u) for u in urls] |
| 66 | + |
| 67 | + cwe_ids = advisory.get("cwe_ids") or [] |
| 68 | + cwe_list = list(map(get_cwe_id, cwe_ids)) |
| 69 | + |
| 70 | + date_published = dateparser.parse(advisory.get("pubdate")) if advisory.get("pubdate") else None |
| 71 | + if date_published: |
| 72 | + date_published = date_published.replace(tzinfo=pytz.UTC) |
| 73 | + |
| 74 | + # Prefer a version-less PURL derived from package_slug for affected/fixed ranges |
| 75 | + purl_for_package = None |
| 76 | + if package_slug: |
| 77 | + purl_for_package = get_purl_fn( |
| 78 | + package_slug=package_slug, |
| 79 | + purl_type_by_gitlab_scheme=purl_type_by_gitlab_scheme, |
| 80 | + logger=logger, |
| 81 | + ) |
| 82 | + |
| 83 | + if not purl_for_package: |
| 84 | + logger( |
| 85 | + f"advisory_dict_to_advisory_data: purl is not valid: {package_slug!r}", |
| 86 | + level=logging.ERROR, |
| 87 | + ) |
| 88 | + return AdvisoryData( |
| 89 | + advisory_id=advisory_id, |
| 90 | + aliases=aliases, |
| 91 | + summary=summary, |
| 92 | + references_v2=references, |
| 93 | + date_published=date_published, |
| 94 | + url=advisory_url, |
| 95 | + original_advisory_text=json.dumps(advisory, indent=2, ensure_ascii=False), |
| 96 | + ) |
| 97 | + |
| 98 | + # Compute affected and fixed ranges |
| 99 | + affected_version_range = None |
| 100 | + fixed_versions = advisory.get("fixed_versions") or [] |
| 101 | + affected_range = advisory.get("affected_range") |
| 102 | + gitlab_native_schemes = {"pypi", "gem", "npm", "go", "packagist", "conan"} |
| 103 | + vrc = RANGE_CLASS_BY_SCHEMES[purl_for_package.type] |
| 104 | + gitlab_scheme = gitlab_scheme_by_purl_type[purl_for_package.type] |
| 105 | + try: |
| 106 | + if affected_range: |
| 107 | + if gitlab_scheme in gitlab_native_schemes: |
| 108 | + affected_version_range = from_gitlab_native( |
| 109 | + gitlab_scheme=gitlab_scheme, string=affected_range |
| 110 | + ) |
| 111 | + else: |
| 112 | + affected_version_range = vrc.from_native(affected_range) |
| 113 | + except Exception as e: |
| 114 | + logger( |
| 115 | + ( |
| 116 | + "advisory_dict_to_advisory_data: affected_range is not parsable: " |
| 117 | + f"{affected_range!r} for: {purl_for_package!s} error: {e!r}\n {traceback.format_exc()}" |
| 118 | + ), |
| 119 | + level=logging.ERROR, |
| 120 | + ) |
| 121 | + |
| 122 | + parsed_fixed_versions = [] |
| 123 | + for fixed_version in fixed_versions: |
| 124 | + try: |
| 125 | + fixed_version = vrc.version_class(fixed_version) |
| 126 | + parsed_fixed_versions.append(fixed_version.string) |
| 127 | + except Exception as e: |
| 128 | + logger( |
| 129 | + ( |
| 130 | + "advisory_dict_to_advisory_data: fixed_version is not parsable`: " |
| 131 | + f"{fixed_version!r} error: {e!r}\n {traceback.format_exc()}" |
| 132 | + ), |
| 133 | + level=logging.ERROR, |
| 134 | + ) |
| 135 | + |
| 136 | + if affected_version_range: |
| 137 | + vrc = affected_version_range.__class__ |
| 138 | + |
| 139 | + fixed_version_range = vrc.from_versions(parsed_fixed_versions) |
| 140 | + if not fixed_version_range and not affected_version_range: |
| 141 | + return |
| 142 | + |
| 143 | + affected_package = AffectedPackageV2( |
| 144 | + package=purl_for_package, |
| 145 | + affected_version_range=affected_version_range, |
| 146 | + fixed_version_range=fixed_version_range, |
| 147 | + ) |
| 148 | + |
| 149 | + # Build a default advisory URL if not provided |
| 150 | + if not advisory_url and package_slug and identifier: |
| 151 | + from urllib.parse import urljoin |
| 152 | + |
| 153 | + advisory_url = urljoin( |
| 154 | + "https://gitlab.com/gitlab-org/advisories-community/-/blob/main/", |
| 155 | + package_slug + "/" + identifier + ".yml", |
| 156 | + ) |
| 157 | + |
| 158 | + return AdvisoryData( |
| 159 | + advisory_id=advisory_id, |
| 160 | + aliases=aliases, |
| 161 | + summary=summary, |
| 162 | + references_v2=references, |
| 163 | + date_published=date_published, |
| 164 | + affected_packages=[affected_package], |
| 165 | + weaknesses=cwe_list, |
| 166 | + url=advisory_url, |
| 167 | + original_advisory_text=json.dumps(advisory, indent=2, ensure_ascii=False), |
| 168 | + ) |
0 commit comments