feat(scan): include optional EPSS fields in vulns JSON - #336
Closed
vibgrate-team wants to merge 1 commit into
Closed
vibgrate-team wants to merge 1 commit into
vibgrate-team wants to merge 1 commit into
Conversation
Surface EPSS, percentile, and KEV on vg scan --vulns advisories when the advisory body or package manifest already carries them. Absent signals stay null and are never coerced to 0, and offline scans do not fetch EPSS. Fixes #253 Signed-off-by: Cursor Agent <cursoragent@cursor.com> Co-authored-by: vibgrate-team <vibgrate-team@users.noreply.github.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
vg scan --vulnsJSON now copies exploitability signals onto each advisory inextended.vulnerabilitieswhen the advisory body or a--package-manifestbundle already has them:epss— FIRST EPSS probability, 0–1epssPercentile— EPSS percentile, 0–1kev— CISA KEV flag when the source recorded oneA missing signal is
null. A real score of0is kept. Absence is never written as0, and the scan does not fetch EPSS (offline and--package-manifestincluded). Advisory order is unchanged (severity, then id). Text and SARIF findings stay as they are.Why
Severity and CVSS do not rank urgency. When the local advisory data already carries EPSS or KEV, CI and agents should be able to sort from the scan JSON without a second tool, still local-first.
Verify
pnpm test— 4906 passedpnpm lint— clean (pre-existing unused-var warnings only)pnpm typecheck— cleanfetch, writes the scores into JSON, and leaves unspecified percentile/KEV asnull0, out-of-range and non-numeric values (null, not coerced), string scores already on the advisory, and stable severity/id orderingRelated issues
Fixes #253
Checklist
pnpm testpassespnpm lintis cleanpnpm typecheckis cleangraph.json/ report output (content-hashed IDs, stable sorts; no time, randomness, or filesystem-order dependence)git commit -s, DCO)Notes for reviewers
EPSS is read from fields already on the advisory (
epss,epssPercentile/epss_percentile,kev/cisa_kev, or a nestedexploitabilityobject). Manifest entries use the same names. No FIRST or other EPSS endpoint was added. SARIF properties and the human finding line still carry severity, CVSS, and the fixing version only.