Skip to content

Commit 759a090

Browse files
committed
Add data migration for old npm and pypa advisory
- Update the created_by field on old advisory to new pipeline_id Signed-off-by: Keshav Priyadarshi <git@keshav.space>
1 parent c606c73 commit 759a090

File tree

4 files changed

+122
-3
lines changed

4 files changed

+122
-3
lines changed
Lines changed: 46 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,46 @@
1+
# Generated by Django 4.2.15 on 2024-09-12 12:56
2+
3+
from django.db import migrations
4+
5+
"""
6+
Update the created_by field on Advisory from the old qualified_name
7+
to the new pipeline_id.
8+
"""
9+
10+
11+
def update_created_by(apps, schema_editor):
12+
from vulnerabilities.pipelines.npm_importer import NpmImporterPipeline
13+
from vulnerabilities.pipelines.pypa_importer import PyPaImporterPipeline
14+
15+
Advisory = apps.get_model("vulnerabilities", "Advisory")
16+
Advisory.objects.filter(created_by="vulnerabilities.importers.npm.NpmImporter").update(
17+
created_by=NpmImporterPipeline.pipeline_id
18+
)
19+
Advisory.objects.filter(created_by="vulnerabilities.importers.pypa.PyPaImporter").update(
20+
created_by=PyPaImporterPipeline.pipeline_id
21+
)
22+
23+
24+
25+
def reverse_update_created_by(apps, schema_editor):
26+
from vulnerabilities.pipelines.npm_importer import NpmImporterPipeline
27+
from vulnerabilities.pipelines.pypa_importer import PyPaImporterPipeline
28+
29+
Advisory = apps.get_model("vulnerabilities", "Advisory")
30+
Advisory.objects.filter(created_by=NpmImporterPipeline.pipeline_id).update(
31+
created_by="vulnerabilities.importers.npm.NpmImporter"
32+
)
33+
Advisory.objects.filter(created_by=PyPaImporterPipeline.pipeline_id).update(
34+
created_by="vulnerabilities.importers.pypa.PyPaImporter"
35+
)
36+
37+
38+
class Migration(migrations.Migration):
39+
40+
dependencies = [
41+
("vulnerabilities", "0062_package_is_ghost"),
42+
]
43+
44+
operations = [
45+
migrations.RunPython(update_created_by, reverse_code=reverse_update_created_by),
46+
]

vulnerabilities/pipelines/npm_importer.py

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -32,6 +32,8 @@
3232
class NpmImporterPipeline(VulnerableCodeBaseImporterPipeline):
3333
"""Collect advisories from nodejs GitHub repository."""
3434

35+
pipeline_id = "npm_importer"
36+
3537
spdx_license_expression = "MIT"
3638
license_url = "https://github.com/nodejs/security-wg/blob/main/LICENSE.md"
3739
repo_url = "git+https://github.com/nodejs/security-wg"

vulnerabilities/tests/test_changelog.py

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -23,7 +23,7 @@ def test_package_changelog():
2323
pkg, _ = Package.objects.get_or_create_from_purl("pkg:npm/foo@1.0.0")
2424
assert PackageChangeLog.objects.filter(package=pkg).count() == 0
2525
adv = Advisory.objects.create(
26-
created_by=NpmImporterPipeline.qualified_name,
26+
created_by=NpmImporterPipeline.pipeline_id,
2727
summary="TEST",
2828
date_collected=datetime.now(),
2929
url="https://test.com/source",
@@ -49,7 +49,7 @@ def test_package_changelog():
4949
pkg1, _ = Package.objects.get_or_create_from_purl("pkg:npm/foo@2.0.0")
5050
assert PackageChangeLog.objects.filter(package=pkg1).count() == 0
5151
adv = Advisory.objects.create(
52-
created_by=NpmImporterPipeline.qualified_name,
52+
created_by=NpmImporterPipeline.pipeline_id,
5353
summary="TEST-1",
5454
date_collected=datetime.now(),
5555
url="https://test.com/source-1",
@@ -79,7 +79,7 @@ def test_package_changelog():
7979
@pytest.mark.django_db
8080
def test_vulnerability_changelog():
8181
adv = Advisory.objects.create(
82-
created_by=NpmImporterPipeline.qualified_name,
82+
created_by=NpmImporterPipeline.pipeline_id,
8383
summary="TEST_1",
8484
date_collected=datetime.now(),
8585
url="https://test.com/source",

vulnerabilities/tests/test_data_migrations.py

Lines changed: 71 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -11,8 +11,14 @@
1111
from django.db import connection
1212
from django.db.migrations.executor import MigrationExecutor
1313
from django.test import TestCase
14+
from django.utils import timezone
15+
from packageurl import PackageURL
16+
from univers.version_range import VersionRange
1417

1518
from vulnerabilities import severity_systems
19+
from vulnerabilities.importer import AdvisoryData
20+
from vulnerabilities.importer import AffectedPackage
21+
from vulnerabilities.importer import Reference
1622

1723

1824
class TestMigrations(TestCase):
@@ -610,3 +616,68 @@ def setUpBeforeMigration(self, apps):
610616
def test_removal_of_duped_purls(self):
611617
Package = apps.get_model("vulnerabilities", "Package")
612618
assert Package.objects.count() == 1
619+
620+
621+
class TestUpdateNpmPypaAdvisoryCreatedByField(TestMigrations):
622+
app_name = "vulnerabilities"
623+
migrate_from = "0062_package_is_ghost"
624+
migrate_to = "0063_update_npm_pypa_advisory_created_by"
625+
626+
advisory_data1 = AdvisoryData(
627+
aliases=["CVE-2020-13371337"],
628+
summary="vulnerability description here",
629+
affected_packages=[
630+
AffectedPackage(
631+
package=PackageURL(type="npm", name="dummy"),
632+
affected_version_range=VersionRange.from_string("vers:npm/>=1.0.0|<=2.0.0"),
633+
)
634+
],
635+
references=[Reference(url="https://example.com/with/more/info/CVE-2020-13371337")],
636+
date_published=timezone.now(),
637+
url="https://test.com",
638+
)
639+
advisory_data2 = AdvisoryData(
640+
aliases=["CVE-2020-1337"],
641+
summary="vulnerability description here",
642+
affected_packages=[
643+
AffectedPackage(
644+
package=PackageURL(type="pypi", name="dummy"),
645+
affected_version_range=VersionRange.from_string("vers:pypi/>=1.0.0|<=2.0.0"),
646+
)
647+
],
648+
references=[Reference(url="https://example.com/with/more/info/CVE-2020-1337")],
649+
date_published=timezone.now(),
650+
url="https://test2.com",
651+
)
652+
653+
def setUpBeforeMigration(self, apps):
654+
Advisory = apps.get_model("vulnerabilities", "Advisory")
655+
adv1 = Advisory.objects.create(
656+
aliases=self.advisory_data1.aliases,
657+
summary=self.advisory_data1.summary,
658+
affected_packages=[pkg.to_dict() for pkg in self.advisory_data1.affected_packages],
659+
references=[ref.to_dict() for ref in self.advisory_data1.references],
660+
url=self.advisory_data1.url,
661+
created_by="vulnerabilities.importers.npm.NpmImporter",
662+
date_collected=timezone.now(),
663+
)
664+
665+
adv2 = Advisory.objects.create(
666+
aliases=self.advisory_data2.aliases,
667+
summary=self.advisory_data2.summary,
668+
affected_packages=[pkg.to_dict() for pkg in self.advisory_data2.affected_packages],
669+
references=[ref.to_dict() for ref in self.advisory_data2.references],
670+
url=self.advisory_data2.url,
671+
created_by="vulnerabilities.importers.pypa.PyPaImporter",
672+
date_collected=timezone.now(),
673+
)
674+
675+
def test_removal_of_duped_purls(self):
676+
Advisory = apps.get_model("vulnerabilities", "Advisory")
677+
adv = Advisory.objects.all()
678+
679+
assert adv.filter(created_by="vulnerabilities.importers.pypa.PyPaImporter").count() == 0
680+
assert adv.filter(created_by="pypa_importer").count() == 1
681+
682+
assert adv.filter(created_by="vulnerabilities.importers.npm.NpmImporter").count() == 0
683+
assert adv.filter(created_by="npm_importer").count() == 1

0 commit comments

Comments
 (0)