Skip to content

feat(scan): include optional EPSS fields in vulns JSON - #336

Closed
vibgrate-team wants to merge 1 commit into
mainfrom
cursor/vulns-epss-json-14ab
Closed

vibgrate-team wants to merge 1 commit into
mainfrom
cursor/vulns-epss-json-14ab

Conversation

@vibgrate-team

Copy link
Copy Markdown
Contributor

Summary

vg scan --vulns JSON now copies exploitability signals onto each advisory in extended.vulnerabilities when the advisory body or a --package-manifest bundle already has them:

  • epss — FIRST EPSS probability, 0–1
  • epssPercentile — EPSS percentile, 0–1
  • kev — CISA KEV flag when the source recorded one

A missing signal is null. A real score of 0 is kept. Absence is never written as 0, and the scan does not fetch EPSS (offline and --package-manifest included). Advisory order is unchanged (severity, then id). Text and SARIF findings stay as they are.

Why

Severity and CVSS do not rank urgency. When the local advisory data already carries EPSS or KEV, CI and agents should be able to sort from the scan JSON without a second tool, still local-first.

Verify

  • pnpm test — 4906 passed
  • pnpm lint — clean (pre-existing unused-var warnings only)
  • pnpm typecheck — clean
  • Offline scan with a manifest that carries EPSS does not call fetch, writes the scores into JSON, and leaves unspecified percentile/KEV as null
  • Unit tests cover a real 0, out-of-range and non-numeric values (null, not coerced), string scores already on the advisory, and stable severity/id ordering

Related issues

Fixes #253

Checklist

  • pnpm test passes
  • pnpm lint is clean
  • pnpm typecheck is clean
  • Docs updated (README / DOCS / ARCHITECTURE) where behavior changed
  • Determinism preserved — identical input still produces identical graph.json / report output (content-hashed IDs, stable sorts; no time, randomness, or filesystem-order dependence)
  • No proprietary or internal references — public, Apache-2.0 content only
  • Commits use Conventional Commits and are signed off (git commit -s, DCO)

Notes for reviewers

EPSS is read from fields already on the advisory (epss, epssPercentile / epss_percentile, kev / cisa_kev, or a nested exploitability object). Manifest entries use the same names. No FIRST or other EPSS endpoint was added. SARIF properties and the human finding line still carry severity, CVSS, and the fixing version only.

Open in Web Open in Cursor 

Surface EPSS, percentile, and KEV on vg scan --vulns advisories when the
advisory body or package manifest already carries them. Absent signals
stay null and are never coerced to 0, and offline scans do not fetch EPSS.

Fixes #253

Signed-off-by: Cursor Agent <cursoragent@cursor.com>

Co-authored-by: vibgrate-team <vibgrate-team@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Enhancement: include EPSS/exploitability fields in vg scan --vulns JSON when present

2 participants