Skip to content

fix: skip affected packages for "Not affected" Arch Linux AVGs - #2457

Open
Sahil-u07 wants to merge 1 commit into
aboutcode-org:mainfrom
Sahil-u07:fix-archlinux-not-affected-status
Open

Sahil-u07 wants to merge 1 commit into
aboutcode-org:mainfrom
Sahil-u07:fix-archlinux-not-affected-status

Conversation

@Sahil-u07

Copy link
Copy Markdown

The Arch Linux importer doesn't read the status field of an AVG, so records marked "Not affected" upstream get imported as if the package were vulnerable.

For example AVG-2737 (gnome-remote-desktop, CVE-2022-1736) is "Not affected", but it's imported with affected 42.1-1 and fixed 42.1.1-1.

This keeps the advisory so its aliases and references are still stored, but skips the affected packages for "Not affected" records. Added a test using the AVG-2737 record.

I left the "Vulnerable" records with no fixed version and the "Unknown" ones alone for now. Happy to look at those in a follow-up if that's useful.

The Arch importer never looked at the AVG status, so records marked
"Not affected" were imported as affecting the listed packages. For
example AVG-2737 showed gnome-remote-desktop 42.1-1 as affected.

Keep the advisory so its aliases and references are still recorded,
but do not attach any affected packages to it.

Signed-off-by: Sahil Lenka <sahillenka44@gmail.com>
Copilot AI balanced review requested due to automatic review settings October 1, 2026 06:21

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants