feat(vulnfeeds): handle rejected CVEs and propagate withdrawn status - #5761
Open
jess-lowe wants to merge 11 commits into
Open
feat(vulnfeeds): handle rejected CVEs and propagate withdrawn status#5761jess-lowe wants to merge 11 commits into
jess-lowe wants to merge 11 commits into
Conversation
another-rex
reviewed
Aug 3, 2026
another-rex
left a comment
Contributor
There was a problem hiding this comment.
If a rejected CVE is brand new to us, we ignore it.
Should we also just be publishing withdrawn entires for them rather than ignoring it?
At least, should we be doing this in the cve and nvd versions, and then in combine-to-osv decide whether to publish it. (To avoid cases where it's withdrawn in nvd, but there in cve, and we're just publishing it as if cve is the only source and not correctly marking it as withdrawn.)
another-rex
reviewed
Aug 3, 2026
another-rex
reviewed
Aug 3, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
If a CVE is marked as Rejected upstream (in NVD or CVEList), OSV will now handle it properly instead of ignoring the change or keeping stale data.
How it works
(Tested and verified with local scripts and unit tests).
Closes #4610