Skip to content

fedcode-next: Extract fix commits from the commit logs in search for CVE-related commit messages #2000

Description

@pombredanne

We should create a pipeline that extract fix commits by parsing commit messages there is multiple way we for doing that

  • Use a single simple regular expression. ex CVE-\d{4}-\d{4,7}
  • Apply multiple regular expressions with a k-top ranking strategy.
  • Develop a machine learning model to extract the most relevant fix commits.

Tools Using Similar Approaches to Parse Git Commit Messages:

Activity

  1. ziadhany commented on Feb 12, 2026

    @ziadhany
    Collaborator

    This has been completed. We now have a new importer named "collect_fix_commits" that does the job. It has been merged with this PR:

    We further fine tune the pipeline on the list of project listed below.

    See the collected commits attached for reference:
    vulnerabilities_packagecommitpatch.zip

    These are the repositories we use to fine tune the data collection:

    There is further work that will continue for this feature in:

  2. moved this from Done to Under review in 00-AboutCodePlanneron May 28, 2026
  3. moved this from Reviewed to Validated in 00-AboutCodePlanneron Aug 7, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

No labels
No labels

Type

No type

Projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions