Skip to content

fix(sc4): align report guidance with vulnerability evidence - #692

Open
agentsope wants to merge 1 commit into
NVIDIA:mainfrom
agentsope:fix/673-sc4-evidence-wording
Open

agentsope wants to merge 1 commit into
NVIDIA:mainfrom
agentsope:fix/673-sc4-evidence-wording

Conversation

@agentsope

Copy link
Copy Markdown
Contributor

SC4 findings for an unknown dependency version or a failed OSV lookup inherit the generic explanation that the dependency has known vulnerabilities and should be upgraded to a patched version. For example, a package-name-only lookup correctly says the installed release may not be affected, while its explanation claims a confirmed vulnerability.

Provide evidence-specific explanations and remediation at each SC4 finding source. Unknown versions direct users to resolve and check the actual version; failed lookups describe incomplete coverage and recommend retrying. Confirmed OSV matches recommend consulting the advisories and upgrading only if a fixed release exists. Static fallback matches retain their evidence and use the recorded fixed-version threshold when available.

Finding messages, severity, confidence, detection logic, and incomplete-coverage accounting remain unchanged.

Closes #673.

Validation

  • 17 new offline regression cases cover unknown and resolved versions, failed lookups, positive fallback evidence, successful empty results, partial analyzer status, and JSON/Markdown/SARIF guidance.
  • Before the source fix, the initial 11-case selection had 10 failures and 1 passing empty-result control.
  • Related analyzer, OSV client, lockfile, static-runner, and report suites: 930 passed.
  • Repository-wide Ruff lint and format checks, targeted mypy, and git diff --check passed.

All advisory and failure responses in the new tests are simulated; no live database outage or real package vulnerability is claimed.

Signed-off-by: Whj9283 <1621370123@qq.com>
Copilot AI balanced review requested due to automatic review settings September 30, 2026 07:04

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

SC4 uses confirmed-vulnerability wording for unknown versions and failed lookups

2 participants