Skip to content

fix(report): show fix-available hints in vg scan and vg report text - #334

Closed
vibgrate-team wants to merge 1 commit into
mainfrom
cursor/scan-fix-available-hint-325b
Closed

vibgrate-team wants to merge 1 commit into
mainfrom
cursor/scan-fix-available-hint-325b

Conversation

@vibgrate-team

Copy link
Copy Markdown
Contributor

Summary

vg scan and vg report text output now follow a finding with fix available: … when the scan payload already names a fixed version (fixedVersions or fixedVersion) or a remediation string. The hint is taken only from fields already on the finding — no network lookup.

When that metadata is missing or empty, the line is omitted. Vulnerability finding messages no longer append "no fix available", and stored messages that still end with that phrase drop it in human text. vg why uses the same rule for advisory lines.

JSON and SARIF are unchanged: fix versions stay on finding details (and therefore SARIF properties).

Related issues

Fixes #209

Checklist

  • pnpm test passes
  • pnpm lint is clean
  • pnpm typecheck is clean
  • Docs updated (README / DOCS / ARCHITECTURE) where behavior changed
  • Determinism preserved — identical input still produces identical
    graph.json / report output (content-hashed IDs, stable sorts; no time,
    randomness, or filesystem-order dependence)
  • No proprietary or internal references — public, Apache-2.0 content only
  • Commits use Conventional Commits and are signed off (git commit -s, DCO)

Notes for reviewers

  • Verify with test/fixtures/fix-available-scan.json: the same artifact renders the same findings block from both the scan text formatter and vg report. Versions are listed in payload order, blanks and duplicates dropped.
  • A finding with an empty fixedVersions array prints no fix line.
  • pnpm test (4903), pnpm lint (exit 0), and pnpm typecheck passed. Lint still reports five pre-existing unused-variable warnings in unrelated files.
Open in Web Open in Cursor 

When a finding already carries a fixed version or remediation, vg scan
and vg report text output follow it with "fix available: …". The hint
is omitted when that metadata is absent, and vulnerability messages no
longer claim "no fix".

Signed-off-by: Cursor Agent <cursoragent@cursor.com>

Co-authored-by: vibgrate-team <vibgrate-team@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Enhancement: surface “fix available” hints in vg scan / report human output

2 participants