Граф коммитов

1068 Коммитов

Автор SHA1 Сообщение Дата
Tatiana Bradley 8cb59f0eba data/reports: add GO-2023-1569.yaml
Aliases: CVE-2022-41725

Updates golang/vulndb#1569

Change-Id: I83b52241f0bbe8f5f247284bd6e6b03dd6edb133
Reviewed-on: https://go-review.googlesource.com/c/vulndb/+/468898
TryBot-Result: Gopher Robot <gobot@golang.org>
Reviewed-by: Damien Neil <dneil@google.com>
Reviewed-by: Tatiana Bradley <tatianabradley@google.com>
Run-TryBot: Tatiana Bradley <tatianabradley@google.com>
2023-02-21 20:44:30 +00:00
Tim King 413c36fb40 all: pull the most recent version of vuln
Change-Id: I866e9c55973f7a2a921a0cc762a593dbbb16b29d
Reviewed-on: https://go-review.googlesource.com/c/vulndb/+/469101
TryBot-Result: Gopher Robot <gobot@golang.org>
Auto-Submit: Tim King <taking@google.com>
Run-TryBot: Tim King <taking@google.com>
Reviewed-by: Zvonimir Pavlinovic <zpavlinovic@google.com>
2023-02-17 21:16:36 +00:00
Tim King 15cb3c90a6 data/reports: add GO-2023-1578.yaml
Aliases: CVE-2023-0475, GHSA-jpxj-2jvg-6jv9

Fixes golang/vulndb#1578

Change-Id: I9bd8aee8936a9c166f3e6eb85613eb29954bc7ea
Reviewed-on: https://go-review.googlesource.com/c/vulndb/+/469100
Run-TryBot: Tim King <taking@google.com>
Reviewed-by: Zvonimir Pavlinovic <zpavlinovic@google.com>
Auto-Submit: Tim King <taking@google.com>
TryBot-Result: Gopher Robot <gobot@golang.org>
2023-02-17 21:16:15 +00:00
Tim King 4aae72da45 data/reports: add GO-2023-1574.yaml
Aliases: CVE-2023-25173, GHSA-hmfx-3pcx-653p

Fixes golang/vulndb#1574

Change-Id: Ia0fe55d91d704974b9df0da6aaf5be72d9528b2a
Reviewed-on: https://go-review.googlesource.com/c/vulndb/+/469099
Run-TryBot: Tim King <taking@google.com>
TryBot-Result: Gopher Robot <gobot@golang.org>
Reviewed-by: Damien Neil <dneil@google.com>
2023-02-17 20:52:58 +00:00
Tim King ece9a054ca data/reports: add GO-2023-1573.yaml
Aliases: CVE-2023-25153, GHSA-259w-8hf6-59c2

Fixes golang/vulndb#1573

Change-Id: I89f90695dd813ea446fb2ed6e521edb4075173ab
Reviewed-on: https://go-review.googlesource.com/c/vulndb/+/468995
Reviewed-by: Damien Neil <dneil@google.com>
Run-TryBot: Tim King <taking@google.com>
TryBot-Result: Gopher Robot <gobot@golang.org>
2023-02-17 19:16:59 +00:00
Tim King 2d838f9120 data/excluded: batch add GO-2023-1577, GO-2023-1560
Fixes golang/vulndb#1577
Fixes golang/vulndb#1560

Change-Id: Ibf3f6ce099450132308f668172d1cc61a44f5932
Reviewed-on: https://go-review.googlesource.com/c/vulndb/+/468975
Auto-Submit: Tim King <taking@google.com>
TryBot-Result: Gopher Robot <gobot@golang.org>
Reviewed-by: Damien Neil <dneil@google.com>
Run-TryBot: Tim King <taking@google.com>
2023-02-17 00:27:58 +00:00
Tatiana Bradley bbfff9b945 data/reports: add GO-2023-1571.yaml
Aliases: CVE-2022-41723

Updates golang/vulndb#1571

Change-Id: Iec81cb886f5e67d37f5b484f59e257431bde4690
Reviewed-on: https://go-review.googlesource.com/c/vulndb/+/468900
Reviewed-by: Tatiana Bradley <tatianabradley@google.com>
TryBot-Result: Gopher Robot <gobot@golang.org>
Run-TryBot: Tatiana Bradley <tatianabradley@google.com>
Reviewed-by: Damien Neil <dneil@google.com>
2023-02-16 22:31:36 +00:00
Tatiana Bradley ba363690f1 data/reports: add GO-2023-1572.yaml
Aliases: CVE-2022-41727

Updates golang/vulndb#1572

Change-Id: I5feb10dc0c30c225ce161c21ee6a3c86bbab665e
Reviewed-on: https://go-review.googlesource.com/c/vulndb/+/468901
TryBot-Result: Gopher Robot <gobot@golang.org>
Run-TryBot: Tatiana Bradley <tatianabradley@google.com>
Reviewed-by: Damien Neil <dneil@google.com>
Reviewed-by: Tatiana Bradley <tatianabradley@google.com>
2023-02-16 22:25:24 +00:00
Tatiana Bradley b7ef72b1f2 data/reports: add GO-2023-1570.yaml
Aliases: CVE-2022-41724

Updates golang/vulndb#1570

Change-Id: I0efdb318fe432ec425e7d018228ebba8c23429b2
Reviewed-on: https://go-review.googlesource.com/c/vulndb/+/468899
Reviewed-by: Tatiana Bradley <tatianabradley@google.com>
TryBot-Result: Gopher Robot <gobot@golang.org>
Reviewed-by: Damien Neil <dneil@google.com>
Run-TryBot: Tatiana Bradley <tatianabradley@google.com>
2023-02-16 22:24:51 +00:00
Tatiana Bradley 67a475b3fe data/reports: add GO-2023-1549.yaml
Aliases: CVE-2023-0229, GHSA-5465-xc2j-6p84

Fixes golang/vulndb#1549

Change-Id: I02fb373c8f0367274d6e6995d62d47518da24ca7
Reviewed-on: https://go-review.googlesource.com/c/vulndb/+/468896
Run-TryBot: Tatiana Bradley <tatianabradley@google.com>
Reviewed-by: Tim King <taking@google.com>
TryBot-Result: Gopher Robot <gobot@golang.org>
Reviewed-by: Tatiana Bradley <tatianabradley@google.com>
2023-02-16 21:56:10 +00:00
Tatiana Bradley dc6d92fa4c data/reports: add GO-2023-1568.yaml
Aliases: CVE-2022-41722

Updates golang/vulndb#1568

Change-Id: Icd6550b10b66ff6fa223c1aad0f7ec33378f89b2
Reviewed-on: https://go-review.googlesource.com/c/vulndb/+/468555
TryBot-Result: Gopher Robot <gobot@golang.org>
Reviewed-by: Damien Neil <dneil@google.com>
Run-TryBot: Tatiana Bradley <tatianabradley@google.com>
Reviewed-by: Tatiana Bradley <tatianabradley@google.com>
2023-02-16 19:49:19 +00:00
Tatiana Bradley 6b5bc57fc4 cmd/vulnreport, internal/report: fix handling of stdlib
Fixes two issues with vulnreport's handling of reports in
the standard library:
- No longer overwrites package name with "std"
- No longer populates "cves" field if cve_metadata is present
  (cve_metadata indicates we assigned the CVE)

Change-Id: I75892fe2464d54fb9e3e6d077518e5e602103c1b
Reviewed-on: https://go-review.googlesource.com/c/vulndb/+/468895
Run-TryBot: Tatiana Bradley <tatianabradley@google.com>
Reviewed-by: Tim King <taking@google.com>
TryBot-Result: Gopher Robot <gobot@golang.org>
2023-02-16 19:02:24 +00:00
Tim King 82fb89b398 data/reports: add GO-2023-1567.yaml
Aliases: GHSA-qpm3-vr34-h8w8

Fixes golang/vulndb#1567

Change-Id: Ic5c65e969a95e9dbf62a278b9fbe749649c33a8d
Reviewed-on: https://go-review.googlesource.com/c/vulndb/+/468696
Reviewed-by: Tatiana Bradley <tatianabradley@google.com>
TryBot-Result: Gopher Robot <gobot@golang.org>
Run-TryBot: Tim King <taking@google.com>
2023-02-16 18:37:09 +00:00
Tim King 94a19175cb data/excluded: batch add GO-2023-1565, GO-2023-1564, GO-2023-1563, GO-2023-1562
Fixes golang/vulndb#1565
Fixes golang/vulndb#1564
Fixes golang/vulndb#1563
Fixes golang/vulndb#1562

Change-Id: I9506decbd7be76979471ef2b2dc3a078f90ca105
Reviewed-on: https://go-review.googlesource.com/c/vulndb/+/468595
Run-TryBot: Tim King <taking@google.com>
Reviewed-by: Tatiana Bradley <tatianabradley@google.com>
TryBot-Result: Gopher Robot <gobot@golang.org>
2023-02-16 18:29:04 +00:00
Tim King 78419f21ce data/reports: add GO-2023-1566.yaml
Aliases: CVE-2022-25978, GHSA-9w8x-5hv5-r6gw

Fixes golang/vulndb#1566

Change-Id: Ic830c62f8b06c3637a642af94d50ec50c2347ad7
Reviewed-on: https://go-review.googlesource.com/c/vulndb/+/468637
Run-TryBot: Tim King <taking@google.com>
TryBot-Result: Gopher Robot <gobot@golang.org>
Reviewed-by: Damien Neil <dneil@google.com>
2023-02-15 23:55:24 +00:00
Tatiana Bradley a72c845b48 data/reports: add GO-2023-1548.yaml
Aliases: CVE-2023-25163, GHSA-mv6w-j4xc-qpfw

Fixes golang/vulndb#1548

Change-Id: If5f4bbf6af4926b0e531d3198e05918d02050dac
Reviewed-on: https://go-review.googlesource.com/c/vulndb/+/468316
TryBot-Result: Gopher Robot <gobot@golang.org>
Reviewed-by: Tim King <taking@google.com>
Reviewed-by: Tatiana Bradley <tatianabradley@google.com>
Run-TryBot: Tatiana Bradley <tatianabradley@google.com>
2023-02-15 16:43:39 +00:00
Maceo Thompson 48f52afeb1 data/reports: add GO-2023-1559.yaml
Aliases: CVE-2023-23631, GHSA-4gj3-6r43-3wfc

Fixes golang/vulndb#1559

Change-Id: I99c6b535dd0e90b80ec32060215abe064faa5e99
Reviewed-on: https://go-review.googlesource.com/c/vulndb/+/468177
Run-TryBot: Maceo Thompson <maceothompson@google.com>
Reviewed-by: Tatiana Bradley <tatianabradley@google.com>
TryBot-Result: Gopher Robot <gobot@golang.org>
2023-02-14 19:41:30 +00:00
Maceo Thompson 81e94ecd3d data/reports: add GO-2023-1558.yaml
Aliases: CVE-2023-23626, GHSA-2h6c-j3gf-xp9r

Fixes golang/vulndb#1558

Change-Id: I367cdedd14f78ab57a7a26c6b1417330a18af3a1
Reviewed-on: https://go-review.googlesource.com/c/vulndb/+/468176
Reviewed-by: Tatiana Bradley <tatianabradley@google.com>
TryBot-Result: Gopher Robot <gobot@golang.org>
Run-TryBot: Maceo Thompson <maceothompson@google.com>
2023-02-14 19:41:21 +00:00
Maceo Thompson db6329cbdb data/reports: add GO-2023-1557.yaml
Aliases: CVE-2023-23625, GHSA-q264-w97q-q778

Fixes golang/vulndb#1557

Change-Id: I1fa40c11c16ef5a88357f9d806d7dd92276788da
Reviewed-on: https://go-review.googlesource.com/c/vulndb/+/468175
TryBot-Result: Gopher Robot <gobot@golang.org>
Run-TryBot: Maceo Thompson <maceothompson@google.com>
Reviewed-by: Tatiana Bradley <tatianabradley@google.com>
2023-02-14 19:34:46 +00:00
Maceo Thompson 724632b3fe data/reports: add GO-2023-1519.yaml
Aliases: CVE-2022-31249, GHSA-qrg7-hfx7-95c5

Fixes golang/vulndb#1519

Change-Id: I6be3007b78c545f5b5e5e9ed7a832e200559fd6f
Reviewed-on: https://go-review.googlesource.com/c/vulndb/+/466666
Reviewed-by: Tatiana Bradley <tatianabradley@google.com>
Run-TryBot: Maceo Thompson <maceothompson@google.com>
TryBot-Result: Gopher Robot <gobot@golang.org>
2023-02-14 19:34:35 +00:00
Tatiana Bradley bfe1678d96 internal/report: clean up stdlib handling in CVEToReport
Streamline module/package inferrence for the standard library, and
add assumption that stdlib or x/ repos have CVEs assigned by the Go
CNA (this isn't the case for some older CVEs, but this will capture
the most common case).

Change-Id: I236f8b2fff0e71611ebdb8c1be32f8ed3673e483
Reviewed-on: https://go-review.googlesource.com/c/vulndb/+/467859
Reviewed-by: Tim King <taking@google.com>
Reviewed-by: Tatiana Bradley <tatianabradley@google.com>
Run-TryBot: Tatiana Bradley <tatianabradley@google.com>
TryBot-Result: Gopher Robot <gobot@golang.org>
2023-02-14 19:34:17 +00:00
Tatiana Bradley 0012851fd5 cmd/vulnreport: make ref todos lessy noisy
Avoid adding a TODO for reference types already present in a generated
report.

Change-Id: Ief6e83de23fddd12090c0db4507bce92bfcc2841
Reviewed-on: https://go-review.googlesource.com/c/vulndb/+/467857
Run-TryBot: Tatiana Bradley <tatianabradley@google.com>
Reviewed-by: Tim King <taking@google.com>
TryBot-Result: Gopher Robot <gobot@golang.org>
Reviewed-by: Tatiana Bradley <tatianabradley@google.com>
2023-02-14 16:25:35 +00:00
Maceo Thompson e2b43878b0 data/reports: add GO-2023-1515.yaml
Aliases: CVE-2022-43756, GHSA-8fcj-gf77-47mg

Fixes golang/vulndb#1515

Change-Id: Ie12b030b8859156a869cb91050fd9af7ab8daf05
Reviewed-on: https://go-review.googlesource.com/c/vulndb/+/466665
Run-TryBot: Maceo Thompson <maceothompson@google.com>
TryBot-Result: Gopher Robot <gobot@golang.org>
Reviewed-by: Tatiana Bradley <tatianabradley@google.com>
2023-02-14 16:19:12 +00:00
Maceo Thompson 18450b1d4c data/reports: add GO-2023-1526.yaml
Aliases: CVE-2023-24623

Fixes golang/vulndb#1526

Change-Id: I8caa64d4243f3c6a1803688ec87a3f6e975c2eca
Reviewed-on: https://go-review.googlesource.com/c/vulndb/+/466664
TryBot-Result: Gopher Robot <gobot@golang.org>
Reviewed-by: Tatiana Bradley <tatianabradley@google.com>
Run-TryBot: Maceo Thompson <maceothompson@google.com>
2023-02-14 16:19:07 +00:00
Tatiana Bradley 77cf794e8b data/reports: add GO-2023-1547.yaml
Aliases: CVE-2023-25165, GHSA-pwcw-6f5g-gxf8

Fixes golang/vulndb#1547

Change-Id: If3dcee966bd38d39b667aca8bbdc792f18110688
Reviewed-on: https://go-review.googlesource.com/c/vulndb/+/467855
Reviewed-by: Tatiana Bradley <tatianabradley@google.com>
TryBot-Result: Gopher Robot <gobot@golang.org>
Run-TryBot: Tatiana Bradley <tatianabradley@google.com>
Reviewed-by: Tim King <taking@google.com>
2023-02-14 15:53:55 +00:00
Tatiana Bradley faac2b9c6e internal/report: improve ref type inferrence
Improve "ReferenceType" inference for URLs by allowing more possibilities
and requiring leading and trailing slashes (to reduce false positives).

Change-Id: Ibee7689f88a277aed2776684e45cae7a3d06ec5a
Reviewed-on: https://go-review.googlesource.com/c/vulndb/+/467856
TryBot-Result: Gopher Robot <gobot@golang.org>
Run-TryBot: Tatiana Bradley <tatianabradley@google.com>
Reviewed-by: Damien Neil <dneil@google.com>
Reviewed-by: Tim King <taking@google.com>
2023-02-14 15:49:49 +00:00
Tatiana Bradley 74f61d4446 cmd/vulnreport: remove skip_fix TODO
"skip_fix" is not needed in most cases, so remove the automatic TODO
for it in "vulnreport create".

Change-Id: Id18328e54c061cb3d80413a9f4d68b3f9efe102e
Reviewed-on: https://go-review.googlesource.com/c/vulndb/+/467858
Reviewed-by: Tim King <taking@google.com>
Reviewed-by: Tatiana Bradley <tatianabradley@google.com>
Run-TryBot: Tatiana Bradley <tatianabradley@google.com>
TryBot-Result: Gopher Robot <gobot@golang.org>
2023-02-14 15:48:28 +00:00
Tim King aefe57e503 internal/report: add GHSA references to reports
Change-Id: Ic0419c0686d7e509e70c80ec82cd135b429c981c
Reviewed-on: https://go-review.googlesource.com/c/vulndb/+/467475
Reviewed-by: Tatiana Bradley <tatianabradley@google.com>
Run-TryBot: Tim King <taking@google.com>
TryBot-Result: Gopher Robot <gobot@golang.org>
2023-02-13 17:10:26 +00:00
Tatiana Bradley dce001efde data/reports: add GHSA to GO-2022-0965.yaml
Aliases: GHSA-74fp-r6jw-h4mp

Updates golang/vulndb#965
Fixes golang/vulndb#1538

Change-Id: I383dea54817354e002a0738dfb699cf2d351f577
Reviewed-on: https://go-review.googlesource.com/c/vulndb/+/467438
Reviewed-by: David Chase <drchase@google.com>
Reviewed-by: Damien Neil <dneil@google.com>
Run-TryBot: Tatiana Bradley <tatianabradley@google.com>
TryBot-Result: Gopher Robot <gobot@golang.org>
2023-02-13 16:01:07 +00:00
Tatiana Bradley 0a8e8193e4 data/reports: add GO-2023-1535.yaml
Aliases: GHSA-hxp2-xqf3-v83h

Fixes golang/vulndb#1535

Change-Id: Id27b0960f9d48c8875d81c220d208069ae5c9507
Reviewed-on: https://go-review.googlesource.com/c/vulndb/+/467437
Reviewed-by: Damien Neil <dneil@google.com>
Run-TryBot: Tatiana Bradley <tatianabradley@google.com>
TryBot-Result: Gopher Robot <gobot@golang.org>
Reviewed-by: David Chase <drchase@google.com>
2023-02-13 16:00:55 +00:00
Tatiana Bradley c3b662f93d data/reports: add GO-2023-1534.yaml
Aliases: GHSA-4xgv-j62q-h3rj

Fixes golang/vulndb#1534

Change-Id: I5db478db53707d0631cdb1febc44ba8d97adacae
Reviewed-on: https://go-review.googlesource.com/c/vulndb/+/467436
Run-TryBot: Tatiana Bradley <tatianabradley@google.com>
TryBot-Result: Gopher Robot <gobot@golang.org>
Reviewed-by: David Chase <drchase@google.com>
Reviewed-by: Damien Neil <dneil@google.com>
2023-02-13 16:00:43 +00:00
Tatiana Bradley 883be2a7ec cmd/vulnreport: move find GHSA logic to newReport
This allows us to re-use the addGHSA function. Note this does slightly
change the behavior of vulnreport create, as the added GHSAs are not
taken into account when initially creating the report. This does not
matter much with the current implementation, as we arbitrarily choose
one alias to create the report based on.

Change-Id: Ia99eac8aaec603f5fd44f7b9d017957f8147fe06
Reviewed-on: https://go-review.googlesource.com/c/vulndb/+/467295
Reviewed-by: Tim King <taking@google.com>
Run-TryBot: Tatiana Bradley <tatianabradley@google.com>
TryBot-Result: Gopher Robot <gobot@golang.org>
Reviewed-by: David Chase <drchase@google.com>
2023-02-13 16:00:03 +00:00
Tatiana Bradley a6628195a9 data/excluded: batch add excluded reports
Fixes golang/vulndb#1555
Fixes golang/vulndb#1554
Fixes golang/vulndb#1552
Fixes golang/vulndb#1544
Fixes golang/vulndb#1543
Fixes golang/vulndb#1542
Fixes golang/vulndb#1541
Fixes golang/vulndb#1533
Fixes golang/vulndb#1536
Fixes golang/vulndb#1553
Fixes golang/vulndb#1551
Fixes golang/vulndb#1550

Change-Id: Id3902ec0b438153293926a92449eee1d64cc2fde
Reviewed-on: https://go-review.googlesource.com/c/vulndb/+/467396
Run-TryBot: Tatiana Bradley <tatianabradley@google.com>
TryBot-Result: Gopher Robot <gobot@golang.org>
Reviewed-by: Tim King <taking@google.com>
Reviewed-by: Tatiana Bradley <tatianabradley@google.com>
2023-02-10 20:36:26 +00:00
Tatiana Bradley 2c87650018 cmd/vulnreport: add GHSAs by default in vulnreport fix
Change the default behavior of vulnreport fix to pull in all GHSAs
for existing CVEs (this can be turned off via the flag "skip-ghsa").

Also change the behavior to append to the list of GHSAs instead of
overwriting it.

Change-Id: I1bd8363b4868121b8630e988eee4ed598f995c6d
Reviewed-on: https://go-review.googlesource.com/c/vulndb/+/466575
Run-TryBot: Tatiana Bradley <tatianabradley@google.com>
TryBot-Result: Gopher Robot <gobot@golang.org>
Reviewed-by: Damien Neil <dneil@google.com>
Reviewed-by: Tim King <taking@google.com>
2023-02-10 18:06:42 +00:00
Tim King 546c8bfb67 internal/report: lint on missing skip_fix
Change-Id: Ie9f7c667cdd8e2d2413d8a928bf313e1be9ff5b3
Reviewed-on: https://go-review.googlesource.com/c/vulndb/+/464030
Run-TryBot: Tim King <taking@google.com>
Reviewed-by: Tatiana Bradley <tatianabradley@google.com>
TryBot-Result: Gopher Robot <gobot@golang.org>
2023-02-10 17:30:36 +00:00
Zvonimir Pavlinovic 3e07daa967 data/reports: add packages to GO-2021-0053.yaml
The current list of packages is mentioned in the ghsa, but 1) fix
mentions only unmarshal package and 2) even the ghsa description
explicitly mentions a file in the unmarshal package (this file is where
fix happens to be placed).

The current CL lists only unmarshal package and adds two symbols
mentioned in the fix. Note that there are no derived symbols since
the only symbol derived in theory is Generate itself, which already
appears in the set of initial symbols.

Updates golang/vulndb#53

Change-Id: I0a71c86de032b7334c8cb71b4cacb947e0a70d2d
Reviewed-on: https://go-review.googlesource.com/c/vulndb/+/466996
Reviewed-by: Tatiana Bradley <tatianabradley@google.com>
TryBot-Result: Gopher Robot <gobot@golang.org>
Run-TryBot: Zvonimir Pavlinovic <zpavlinovic@google.com>
Reviewed-by: Damien Neil <dneil@google.com>
2023-02-10 16:51:38 +00:00
Tatiana Bradley 1f6d0a67ed cmd/vulnreport: clean up stdlib fix
Pull warnings related to stdlib version into one place and call a new function, IsStdLib, instead of storing a bool "std".

Change-Id: Icbbe5381d0ccd78178ba0eecb8be53a23f06d5f9
Reviewed-on: https://go-review.googlesource.com/c/vulndb/+/466663
TryBot-Result: Gopher Robot <gobot@golang.org>
Run-TryBot: Tatiana Bradley <tatianabradley@google.com>
Reviewed-by: Tim King <taking@google.com>
2023-02-09 17:38:56 +00:00
Tatiana Bradley fc0e5c9b0e cmd/vulnreport: refactor checkReportSymbols
Pull all the functionality into one loop over the modules.

The only behavior change is that we no longer skip a whole report if it contains the "std" module (because some reports contain both "std" and "x/" repos).

Change-Id: Id95f1844d25e672bb11cdcedeea4af5ffe113be5
Reviewed-on: https://go-review.googlesource.com/c/vulndb/+/466662
Run-TryBot: Tatiana Bradley <tatianabradley@google.com>
Reviewed-by: Tim King <taking@google.com>
TryBot-Result: Gopher Robot <gobot@golang.org>
2023-02-09 17:38:41 +00:00
Tatiana Bradley 1bbb6febe9 data/reports: remove fixed version from GO-2022-0564.yaml
v1 does not contain a fix. Our YAML format does not support directly indicating that v2 onwards is fixed, so for now users will need to read the description of the vuln to determine that the fix is to migrate to v2.

Aliases: CVE-2022-31053, GHSA-75rw-34q6-72cr

Updates golang/vulndb#564

Change-Id: I2e39f363ebfbe7387a5bff4535af02f4d3b24d99
Reviewed-on: https://go-review.googlesource.com/c/vulndb/+/466659
TryBot-Result: Gopher Robot <gobot@golang.org>
Run-TryBot: Tatiana Bradley <tatianabradley@google.com>
Reviewed-by: Tim King <taking@google.com>
2023-02-09 17:37:57 +00:00
Maceo Thompson 56e812d65c data/excluded: batch add GO-2023-1527, GO-2023-1524, GO-2023-1516, GO-2023-1514, GO-2023-1513, GO-2023-1511, GO-2023-1520, GO-2023-1512, GO-2023-1517, GO-2023-1518
Fixes golang/vulndb#1527
Fixes golang/vulndb#1524
Fixes golang/vulndb#1516
Fixes golang/vulndb#1514
Fixes golang/vulndb#1513
Fixes golang/vulndb#1511
Fixes golang/vulndb#1520
Fixes golang/vulndb#1512
Fixes golang/vulndb#1517
Fixes golang/vulndb#1518
Fixes golang/vulndb#1517

Change-Id: Icbda7a3b2474fb21b0aa9a3b4a15cea402199264
Reviewed-on: https://go-review.googlesource.com/c/vulndb/+/466475
Run-TryBot: Maceo Thompson <maceothompson@google.com>
TryBot-Result: Gopher Robot <gobot@golang.org>
Reviewed-by: Tatiana Bradley <tatianabradley@google.com>
2023-02-09 16:29:51 +00:00
Tatiana Bradley c0d4f91266 data/reports: add skip_fix to some cmd reports
Change-Id: Idafd1f4a261e5c4f95f16f2975a782805ea0793a
Reviewed-on: https://go-review.googlesource.com/c/vulndb/+/466661
Run-TryBot: Tatiana Bradley <tatianabradley@google.com>
Reviewed-by: Tim King <taking@google.com>
TryBot-Result: Gopher Robot <gobot@golang.org>
2023-02-08 20:38:52 +00:00
Tatiana Bradley 1ff0a703e5 cmd/vulnreport: in fix, check packages even if no symbols
Vulnreport fix now checks packages (e.g., whether a package exists)
even if there are no symbols to check (unless skip_fix is set).

Change-Id: I09935c1f778ed0e08eeb411111177f328d026513
Reviewed-on: https://go-review.googlesource.com/c/vulndb/+/466657
TryBot-Result: Gopher Robot <gobot@golang.org>
Reviewed-by: Tim King <taking@google.com>
Run-TryBot: Tatiana Bradley <tatianabradley@google.com>
2023-02-08 20:38:42 +00:00
Tatiana Bradley 3828f30271 data/reports: add symbol to GO-2022-1213.yaml
Aliases: CVE-2018-25060, GHSA-hhxg-px5h-jc32

Updates golang/vulndb#1213

Change-Id: Icdd4e887a18002e6864e974efb6a7d5ca4ddf891
Reviewed-on: https://go-review.googlesource.com/c/vulndb/+/466660
TryBot-Result: Gopher Robot <gobot@golang.org>
Reviewed-by: Tim King <taking@google.com>
Run-TryBot: Tatiana Bradley <tatianabradley@google.com>
2023-02-08 20:33:16 +00:00
Tatiana Bradley cc4a08a266 data/reports: add packages to GO-2021-0053.yaml
Listed package was a module, not a package

Aliases: CVE-2021-3121, GHSA-c3h9-896r-86jm

Updates golang/vulndb#53

Change-Id: Iea87cda17b8b2885331fc5872c700525e37af72b
Reviewed-on: https://go-review.googlesource.com/c/vulndb/+/466658
Run-TryBot: Tatiana Bradley <tatianabradley@google.com>
Reviewed-by: Tim King <taking@google.com>
TryBot-Result: Gopher Robot <gobot@golang.org>
2023-02-08 20:33:06 +00:00
Tatiana Bradley 2fcfeff930 data/reports: add missing GHSAs
These GHSAs were found by a modification of the behavior of vulnreport
fix.

Change-Id: I72415e876d84d30f81896108421d5bf998018c4f
Reviewed-on: https://go-review.googlesource.com/c/vulndb/+/466576
Reviewed-by: Tim King <taking@google.com>
TryBot-Result: Gopher Robot <gobot@golang.org>
Reviewed-by: Tatiana Bradley <tatianabradley@google.com>
Run-TryBot: Tatiana Bradley <tatianabradley@google.com>
2023-02-08 18:46:18 +00:00
Tatiana Bradley 3d42cf3203 data/reports: add GHSA to GO-2021-0094.yaml
Aliases: CVE-2020-29529, GHSA-2g5j-5x95-r6hr

Updates golang/vulndb#94

Change-Id: I87c8fec4db7e920b2335ffb56e9851b1f7bd9a34
Reviewed-on: https://go-review.googlesource.com/c/vulndb/+/466142
Reviewed-by: Tim King <taking@google.com>
Auto-Submit: Tatiana Bradley <tatianabradley@google.com>
Run-TryBot: Tatiana Bradley <tatianabradley@google.com>
TryBot-Result: Gopher Robot <gobot@golang.org>
2023-02-07 21:49:55 +00:00
Tatiana Bradley b4cc423062 data/reports: add GHSA to GO-2021-0072.yaml
Aliases: CVE-2017-11468, GHSA-h62f-wm92-2cmw

Updates golang/vulndb#72

Change-Id: I2dda7ff592286446fbc54492899fcd2fa2f9d52c
Reviewed-on: https://go-review.googlesource.com/c/vulndb/+/466141
Reviewed-by: Tim King <taking@google.com>
Auto-Submit: Tatiana Bradley <tatianabradley@google.com>
Run-TryBot: Tatiana Bradley <tatianabradley@google.com>
TryBot-Result: Gopher Robot <gobot@golang.org>
2023-02-07 21:49:53 +00:00
Tatiana Bradley 80ac1f6bb6 data/reports: add GHSA to GO-2021-0066.yaml
Aliases: CVE-2020-8564, GHSA-8mjg-8c8g-6h85

Updates golang/vulndb#66

Change-Id: Ie2e5142aeefc8b2b1f9ff3637e8890b1b2480fa6
Reviewed-on: https://go-review.googlesource.com/c/vulndb/+/466140
Run-TryBot: Tatiana Bradley <tatianabradley@google.com>
Reviewed-by: Tim King <taking@google.com>
Auto-Submit: Tatiana Bradley <tatianabradley@google.com>
TryBot-Result: Gopher Robot <gobot@golang.org>
2023-02-07 21:49:52 +00:00
Tatiana Bradley 52ac4fe838 data/reports: add GHSA to GO-2021-0064.yaml
Aliases: CVE-2020-8565, GHSA-8cfg-vx93-jvxw

Updates golang/vulndb#64

Change-Id: I36bd5136155b44a113e6110bcb0d870b02519112
Reviewed-on: https://go-review.googlesource.com/c/vulndb/+/466139
Run-TryBot: Tatiana Bradley <tatianabradley@google.com>
Auto-Submit: Tatiana Bradley <tatianabradley@google.com>
TryBot-Result: Gopher Robot <gobot@golang.org>
Reviewed-by: Tim King <taking@google.com>
2023-02-07 21:49:50 +00:00
Tatiana Bradley e0054d1148 data/reports: add GHSA to GO-2021-0054.yaml
Aliases: CVE-2020-36067, GHSA-p64j-r5f4-pwwx

Updates golang/vulndb#54

Change-Id: I17568f858b236c66c1a54d51721c0ee572846994
Reviewed-on: https://go-review.googlesource.com/c/vulndb/+/466138
Auto-Submit: Tatiana Bradley <tatianabradley@google.com>
Run-TryBot: Tatiana Bradley <tatianabradley@google.com>
TryBot-Result: Gopher Robot <gobot@golang.org>
Reviewed-by: Tim King <taking@google.com>
2023-02-07 21:49:49 +00:00