feat(report): keep dependency findings from distinct manifests separate in dedupe

This commit is contained in:
Ahmed Allam
2026-08-06 02:20:46 +03:00
committed by Ahmed Allam
parent 72cb15a20a
commit b69af37cb2
3 changed files with 90 additions and 2 deletions
+20
View File
@@ -183,6 +183,24 @@ def _dependency_identity(report: dict[str, Any]) -> tuple[str, str, str] | None:
return cve, ecosystem, package_name
def _manifest_path(report: dict[str, Any]) -> str:
metadata = report.get("dependency_metadata")
if not isinstance(metadata, dict):
return ""
return str(metadata.get("manifest_path") or "").strip()
def _distinct_manifest_paths(candidate: dict[str, Any], report: dict[str, Any]) -> bool:
"""Same CVE/package observed in two different manifests is two findings.
Only applies when both sides carry a manifest_path; a missing path keeps
the legacy CVE/package/ecosystem identity.
"""
candidate_path = _manifest_path(candidate)
report_path = _manifest_path(report)
return bool(candidate_path and report_path and candidate_path != report_path)
def _report_cve(report: dict[str, Any]) -> str:
return str(report.get("cve") or "").strip().upper()
@@ -228,6 +246,8 @@ def _check_dependency_duplicate(
report_cve, report_ecosystem, report_package_name = report_identity
if (report_cve, report_package_name) != (cve, package_name):
continue
if _distinct_manifest_paths(candidate, report):
continue
if report_ecosystem == ecosystem:
return {
"is_duplicate": True,
@@ -77,8 +77,10 @@ For each entry under `.Results[].Vulnerabilities[]` in `trivy-sca.json`, collect
- `CVSS` — the published advisory base score
- `PrimaryURL` / references — to verify the advisory
Deduplicate by `(CVE, PkgName, InstalledVersion)`. File one
`create_dependency_report` per CVE — do not batch multiple CVEs into one report.
Deduplicate by `(CVE, PkgName, Target)` — the same CVE/package observed in two
different manifests (e.g. two workspaces of a monorepo) is two findings, one
per manifest. File one `create_dependency_report` per CVE — do not batch
multiple CVEs into one report.
### Attribute transitive CVEs to the direct dependency