Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

breaking-change(oval): support new goval-dictionary model #1280

Merged
merged 13 commits into from
Sep 13, 2021

Conversation

MaineK00n
Copy link
Collaborator

@MaineK00n MaineK00n commented Aug 10, 2021

Please use this revision with the latest version of goval-dictionary.
Old dictionaries can't detect it correctly.
Since the DB schema has been changed, you have to delete the DB and fetch it again.

vulsio/goval-dictionary@047e4db

What did you implement:

Support changes in the models of goval-dictionary.

Type of change

  • New feature (non-breaking change which adds functionality)

How Has This Been Tested?

$ ./vuls.old report --format-json --refresh-cve --results-dir=(pwd)/integration/results  --config=(pwd)/config.toml 2021-08-11T01:57:56+09:00
[Aug 13 15:01:13]  INFO [localhost] vuls-v0.15.13-build-20210813_145815_d65421c
[Aug 13 15:01:13]  INFO [localhost] Validating config...
[Aug 13 15:01:13]  INFO [localhost] cveDict.type=sqlite3, cveDict.url=, cveDict.SQLite3Path=/usr/share/vuls-data/cve.sqlite3
[Aug 13 15:01:13]  INFO [localhost] ovalDict.type=sqlite3, ovalDict.url=, ovalDict.SQLite3Path=/home/mainek00n/github/github.com/MaineK00n/vuls/oval.master.sqlite3
[Aug 13 15:01:13]  INFO [localhost] gost.type=sqlite3, gost.url=, gost.SQLite3Path=/usr/share/vuls-data/gost.sqlite3
[Aug 13 15:01:13]  INFO [localhost] exploit.type=sqlite3, exploit.url=, exploit.SQLite3Path=/usr/share/vuls-data/go-exploitdb.sqlite3
[Aug 13 15:01:13]  INFO [localhost] metasploit.type=sqlite3, metasploit.url=, metasploit.SQLite3Path=/usr/share/vuls-data/go-msfdb.sqlite3
[Aug 13 15:01:13]  INFO [localhost] Loaded: /home/mainek00n/github/github.com/MaineK00n/vuls/integration/results/2021-08-11T01:57:56+09:00
[Aug 13 15:01:13]  INFO [localhost] OVAL amazon 2 (Karoo) found. defs: 602
[Aug 13 15:01:13]  INFO [localhost] OVAL amazon 2 (Karoo) is fresh. lastModified: 2021-08-13T14:58:03+09:00
[Aug 13 15:01:25]  INFO [localhost] amazon_2: 76 CVEs are detected with OVAL
[Aug 13 15:01:25]  INFO [localhost] amazon_2: 0 unfixed CVEs are detected with gost
[Aug 13 15:01:25]  INFO [localhost] amazon_2: 0 CVEs are detected with CPE
[Aug 13 15:01:25]  INFO [localhost] amazon_2: 1 PoC are detected
[Aug 13 15:01:25]  INFO [localhost] amazon_2: 0 exploits are detected
[Aug 13 15:01:25]  INFO [localhost] OVAL centos 7.7.1908 found. defs: 1296
[Aug 13 15:01:25]  INFO [localhost] OVAL centos 7.7.1908 is fresh. lastModified: 2021-08-13T14:57:17+09:00
[Aug 13 15:01:47]  INFO [localhost] centos_7: 230 CVEs are detected with OVAL
[Aug 13 15:01:48]  INFO [localhost] centos_7: 124 unfixed CVEs are detected with gost
[Aug 13 15:01:48]  INFO [localhost] centos_7: 0 CVEs are detected with CPE
[Aug 13 15:01:49]  INFO [localhost] centos_7: 2 PoC are detected
[Aug 13 15:01:49]  INFO [localhost] centos_7: 2 exploits are detected
[Aug 13 15:01:49]  INFO [localhost] OVAL debian 10 found. defs: 18015
[Aug 13 15:01:49]  INFO [localhost] OVAL debian 10 is fresh. lastModified: 2021-08-13T14:57:29+09:00
[Aug 13 15:01:50]  INFO [localhost] debian_10: 126 CVEs are detected with OVAL
[Aug 13 15:01:52]  INFO [localhost] debian_10: 296 CVEs are detected with gost
[Aug 13 15:01:52]  INFO [localhost] debian_10: 0 CVEs are detected with CPE
[Aug 13 15:01:53]  INFO [localhost] debian_10: 6 PoC are detected
[Aug 13 15:01:53]  INFO [localhost] debian_10: 0 exploits are detected
[Aug 13 15:01:53]  INFO [localhost] OVAL oracle 7.9 found. defs: 20161
[Aug 13 15:01:53]  INFO [localhost] OVAL oracle 7.9 is fresh. lastModified: 2021-08-13T14:57:48+09:00
[Aug 13 15:02:17]  INFO [localhost] oracle: 53 CVEs are detected with OVAL
[Aug 13 15:02:17]  INFO [localhost] oracle: 0 unfixed CVEs are detected with gost
[Aug 13 15:02:17]  INFO [localhost] oracle: 0 CVEs are detected with CPE
[Aug 13 15:02:17]  INFO [localhost] oracle: 1 PoC are detected
[Aug 13 15:02:17]  INFO [localhost] oracle: 0 exploits are detected
[Aug 13 15:02:17]  INFO [localhost] OVAL redhat 7.1 found. defs: 1296
[Aug 13 15:02:17]  INFO [localhost] OVAL redhat 7.1 is fresh. lastModified: 2021-08-13T14:57:17+09:00
[Aug 13 15:02:38]  INFO [localhost] rhel_71: 1200 CVEs are detected with OVAL
[Aug 13 15:02:39]  INFO [localhost] rhel_71: 128 unfixed CVEs are detected with gost
[Aug 13 15:02:39]  INFO [localhost] rhel_71: 0 CVEs are detected with CPE
[Aug 13 15:02:47]  INFO [localhost] rhel_71: 59 PoC are detected
[Aug 13 15:02:47]  INFO [localhost] rhel_71: 18 exploits are detected
[Aug 13 15:02:47]  INFO [localhost] OVAL redhat 8.3 found. defs: 638
[Aug 13 15:02:47]  INFO [localhost] OVAL redhat 8.3 is fresh. lastModified: 2021-08-13T14:57:16+09:00
[Aug 13 15:02:58]  INFO [localhost] rhel_8: 141 CVEs are detected with OVAL
[Aug 13 15:02:58]  INFO [localhost] rhel_8: 91 unfixed CVEs are detected with gost
[Aug 13 15:02:58]  INFO [localhost] rhel_8: 0 CVEs are detected with CPE
[Aug 13 15:02:59]  INFO [localhost] rhel_8: 1 PoC are detected
[Aug 13 15:02:59]  INFO [localhost] rhel_8: 2 exploits are detected
[Aug 13 15:02:59]  INFO [localhost] OVAL ubuntu 18.04 found. defs: 13289
[Aug 13 15:02:59]  INFO [localhost] OVAL ubuntu 18.04 is fresh. lastModified: 2021-08-13T14:57:03+09:00
[Aug 13 15:03:00]  INFO [localhost] ubuntu_1804: 158 CVEs are detected with OVAL
[Aug 13 15:03:04]  INFO [localhost] ubuntu_1804: 15 unfixed CVEs are detected with gost
[Aug 13 15:03:04]  INFO [localhost] ubuntu_1804: 0 CVEs are detected with CPE
[Aug 13 15:03:05]  INFO [localhost] ubuntu_1804: 2 PoC are detected
[Aug 13 15:03:05]  INFO [localhost] ubuntu_1804: 0 exploits are detected
[Aug 13 15:03:05]  INFO [localhost] OVAL ubuntu 20.04 found. defs: 8352
[Aug 13 15:03:05]  INFO [localhost] OVAL ubuntu 20.04 is fresh. lastModified: 2021-08-13T14:56:59+09:00
[Aug 13 15:03:05]  INFO [localhost] ubuntu_2004: 199 CVEs are detected with OVAL
[Aug 13 15:03:08]  INFO [localhost] ubuntu_2004: 5 unfixed CVEs are detected with gost
[Aug 13 15:03:08]  INFO [localhost] ubuntu_2004: 0 CVEs are detected with CPE
[Aug 13 15:03:08]  INFO [localhost] ubuntu_2004: 1 PoC are detected
[Aug 13 15:03:08]  INFO [localhost] ubuntu_2004: 1 exploits are detected

$ ./vuls.new report --format-json --refresh-cve --results-dir=(pwd)/integration/results  --config=(pwd)/config.toml 2021-08-11T01:57:57+09:00
[Aug 13 15:04:21]  INFO [localhost] vuls-v0.15.13-build-20210813_145848_b5c5568
[Aug 13 15:04:21]  INFO [localhost] Validating config...
[Aug 13 15:04:21]  INFO [localhost] cveDict.type=sqlite3, cveDict.url=, cveDict.SQLite3Path=/usr/share/vuls-data/cve.sqlite3
[Aug 13 15:04:21]  INFO [localhost] ovalDict.type=sqlite3, ovalDict.url=, ovalDict.SQLite3Path=/home/mainek00n/github/github.com/MaineK00n/vuls/oval.newmodel.sqlite3
[Aug 13 15:04:21]  INFO [localhost] gost.type=sqlite3, gost.url=, gost.SQLite3Path=/usr/share/vuls-data/gost.sqlite3
[Aug 13 15:04:21]  INFO [localhost] exploit.type=sqlite3, exploit.url=, exploit.SQLite3Path=/usr/share/vuls-data/go-exploitdb.sqlite3
[Aug 13 15:04:21]  INFO [localhost] metasploit.type=sqlite3, metasploit.url=, metasploit.SQLite3Path=/usr/share/vuls-data/go-msfdb.sqlite3
[Aug 13 15:04:21]  INFO [localhost] Loaded: /home/mainek00n/github/github.com/MaineK00n/vuls/integration/results/2021-08-11T01:57:57+09:00
[Aug 13 15:04:21]  INFO [localhost] OVAL amazon 2 (Karoo) found. defs: 602
[Aug 13 15:04:21]  INFO [localhost] OVAL amazon 2 (Karoo) is fresh. lastModified: 2021-08-13T14:55:33+09:00
[Aug 13 15:04:22]  INFO [localhost] amazon_2: 76 CVEs are detected with OVAL
[Aug 13 15:04:22]  INFO [localhost] amazon_2: 0 unfixed CVEs are detected with gost
[Aug 13 15:04:22]  INFO [localhost] amazon_2: 0 CVEs are detected with CPE
[Aug 13 15:04:22]  INFO [localhost] amazon_2: 1 PoC are detected
[Aug 13 15:04:22]  INFO [localhost] amazon_2: 0 exploits are detected
[Aug 13 15:04:22]  INFO [localhost] OVAL centos 7.7.1908 found. defs: 1296
[Aug 13 15:04:22]  INFO [localhost] OVAL centos 7.7.1908 is fresh. lastModified: 2021-08-13T14:55:01+09:00
[Aug 13 15:04:24]  INFO [localhost] centos_7: 230 CVEs are detected with OVAL
[Aug 13 15:04:24]  INFO [localhost] centos_7: 124 unfixed CVEs are detected with gost
[Aug 13 15:04:24]  INFO [localhost] centos_7: 0 CVEs are detected with CPE
[Aug 13 15:04:25]  INFO [localhost] centos_7: 2 PoC are detected
[Aug 13 15:04:25]  INFO [localhost] centos_7: 2 exploits are detected
[Aug 13 15:04:25]  INFO [localhost] OVAL debian 10 found. defs: 22943
[Aug 13 15:04:25]  INFO [localhost] OVAL debian 10 is fresh. lastModified: 2021-08-13T14:55:15+09:00
[Aug 13 15:04:27]  INFO [localhost] debian_10: 126 CVEs are detected with OVAL
[Aug 13 15:04:28]  INFO [localhost] debian_10: 296 CVEs are detected with gost
[Aug 13 15:04:28]  INFO [localhost] debian_10: 0 CVEs are detected with CPE
[Aug 13 15:04:30]  INFO [localhost] debian_10: 6 PoC are detected
[Aug 13 15:04:30]  INFO [localhost] debian_10: 0 exploits are detected
[Aug 13 15:04:30]  INFO [localhost] OVAL oracle 7.9 found. defs: 1574
[Aug 13 15:04:30]  INFO [localhost] OVAL oracle 7.9 is fresh. lastModified: 2021-08-13T14:55:47+09:00
[Aug 13 15:04:31]  INFO [localhost] oracle: 53 CVEs are detected with OVAL
[Aug 13 15:04:31]  INFO [localhost] oracle: 0 unfixed CVEs are detected with gost
[Aug 13 15:04:31]  INFO [localhost] oracle: 0 CVEs are detected with CPE
[Aug 13 15:04:31]  INFO [localhost] oracle: 1 PoC are detected
[Aug 13 15:04:31]  INFO [localhost] oracle: 0 exploits are detected
[Aug 13 15:04:31]  INFO [localhost] OVAL redhat 7.1 found. defs: 1296
[Aug 13 15:04:31]  INFO [localhost] OVAL redhat 7.1 is fresh. lastModified: 2021-08-13T14:55:01+09:00
[Aug 13 15:04:32]  INFO [localhost] rhel_71: 1200 CVEs are detected with OVAL
[Aug 13 15:04:33]  INFO [localhost] rhel_71: 128 unfixed CVEs are detected with gost
[Aug 13 15:04:33]  INFO [localhost] rhel_71: 0 CVEs are detected with CPE
[Aug 13 15:04:39]  INFO [localhost] rhel_71: 59 PoC are detected
[Aug 13 15:04:39]  INFO [localhost] rhel_71: 18 exploits are detected
[Aug 13 15:04:39]  INFO [localhost] OVAL redhat 8.3 found. defs: 638
[Aug 13 15:04:39]  INFO [localhost] OVAL redhat 8.3 is fresh. lastModified: 2021-08-13T14:55:00+09:00
[Aug 13 15:04:40]  INFO [localhost] rhel_8: 141 CVEs are detected with OVAL
[Aug 13 15:04:40]  INFO [localhost] rhel_8: 91 unfixed CVEs are detected with gost
[Aug 13 15:04:40]  INFO [localhost] rhel_8: 0 CVEs are detected with CPE
[Aug 13 15:04:41]  INFO [localhost] rhel_8: 1 PoC are detected
[Aug 13 15:04:41]  INFO [localhost] rhel_8: 2 exploits are detected
[Aug 13 15:04:41]  INFO [localhost] OVAL ubuntu 18.04 found. defs: 13289
[Aug 13 15:04:41]  INFO [localhost] OVAL ubuntu 18.04 is fresh. lastModified: 2021-08-13T14:56:08+09:00
[Aug 13 15:04:43]  INFO [localhost] ubuntu_1804: 158 CVEs are detected with OVAL
[Aug 13 15:04:46]  INFO [localhost] ubuntu_1804: 15 unfixed CVEs are detected with gost
[Aug 13 15:04:46]  INFO [localhost] ubuntu_1804: 0 CVEs are detected with CPE
[Aug 13 15:04:46]  INFO [localhost] ubuntu_1804: 2 PoC are detected
[Aug 13 15:04:46]  INFO [localhost] ubuntu_1804: 0 exploits are detected
[Aug 13 15:04:46]  INFO [localhost] OVAL ubuntu 20.04 found. defs: 8352
[Aug 13 15:04:46]  INFO [localhost] OVAL ubuntu 20.04 is fresh. lastModified: 2021-08-13T14:56:04+09:00
[Aug 13 15:04:48]  INFO [localhost] ubuntu_2004: 199 CVEs are detected with OVAL
[Aug 13 15:04:50]  INFO [localhost] ubuntu_2004: 5 unfixed CVEs are detected with gost
[Aug 13 15:04:50]  INFO [localhost] ubuntu_2004: 0 CVEs are detected with CPE
[Aug 13 15:04:51]  INFO [localhost] ubuntu_2004: 1 PoC are detected
[Aug 13 15:04:51]  INFO [localhost] ubuntu_2004: 1 exploits are detected

Checklist:

You don't have to satisfy all of the following.

  • Write tests
  • Write documentation
  • Check that there aren't other open pull requests for the same issue/feature
  • Format your source code by make fmt
  • Pass the test by make test
  • Provide verification config / commands
  • Enable "Allow edits from maintainers" for this PR
  • Update the messages below

Is this ready for review?: YES

Reference

@MaineK00n
Copy link
Collaborator Author

MaineK00n commented Aug 10, 2021

diff '--color=auto' -c integration/results/2021-08-11T01:57:56+09:00/amazon_2.json integration/results/2021-08-11T01:57:57+09:00/amazon_2.json
*** integration/results/2021-08-11T01:57:56+09:00/amazon_2.json	2021-08-13 15:03:08.893169939 +0900
--- integration/results/2021-08-11T01:57:57+09:00/amazon_2.json	2021-08-13 15:04:51.061305688 +0900
***************
*** 32,40 ****
          "172.17.0.1",
          "172.20.0.1"
      ],
!     "reportedAt": "2021-08-13T15:01:13.786994866+09:00",
      "reportedVersion": "v0.15.13",
!     "reportedRevision": "build-20210813_145815_d65421c",
      "reportedBy": "lize",
      "errors": [],
      "warnings": [],
--- 32,40 ----
          "172.17.0.1",
          "172.20.0.1"
      ],
!     "reportedAt": "2021-08-13T15:04:21.144451039+09:00",
      "reportedVersion": "v0.15.13",
!     "reportedRevision": "build-20210813_145848_b5c5568",
      "reportedBy": "lize",
      "errors": [],
      "warnings": [],
***************
*** 16942,16948 ****
              "ovalDict": {
                  "Name": "ovalDict",
                  "Type": "sqlite3",
!                 "SQLite3Path": "/home/mainek00n/github/github.com/MaineK00n/vuls/oval.master.sqlite3",
                  "DebugSQL": false
              },
              "gost": {
--- 16942,16948 ----
              "ovalDict": {
                  "Name": "ovalDict",
                  "Type": "sqlite3",
!                 "SQLite3Path": "/home/mainek00n/github/github.com/MaineK00n/vuls/oval.newmodel.sqlite3",
                  "DebugSQL": false
              },
              "gost": {
diff '--color=auto' -c integration/results/2021-08-11T01:57:56+09:00/centos_7.json integration/results/2021-08-11T01:57:57+09:00/centos_7.json
*** integration/results/2021-08-11T01:57:56+09:00/centos_7.json	2021-08-13 15:03:08.949172388 +0900
--- integration/results/2021-08-11T01:57:57+09:00/centos_7.json	2021-08-13 15:04:51.161309430 +0900
***************
*** 32,40 ****
          "172.17.0.1",
          "172.20.0.1"
      ],
!     "reportedAt": "2021-08-13T15:01:13.786994866+09:00",
      "reportedVersion": "v0.15.13",
!     "reportedRevision": "build-20210813_145815_d65421c",
      "reportedBy": "lize",
      "errors": [],
      "warnings": [],
--- 32,40 ----
          "172.17.0.1",
          "172.20.0.1"
      ],
!     "reportedAt": "2021-08-13T15:04:21.144451039+09:00",
      "reportedVersion": "v0.15.13",
!     "reportedRevision": "build-20210813_145848_b5c5568",
      "reportedBy": "lize",
      "errors": [],
      "warnings": [],
***************
*** 65207,65213 ****
              "ovalDict": {
                  "Name": "ovalDict",
                  "Type": "sqlite3",
!                 "SQLite3Path": "/home/mainek00n/github/github.com/MaineK00n/vuls/oval.master.sqlite3",
                  "DebugSQL": false
              },
              "gost": {
--- 65207,65213 ----
              "ovalDict": {
                  "Name": "ovalDict",
                  "Type": "sqlite3",
!                 "SQLite3Path": "/home/mainek00n/github/github.com/MaineK00n/vuls/oval.newmodel.sqlite3",
                  "DebugSQL": false
              },
              "gost": {
diff '--color=auto' -c integration/results/2021-08-11T01:57:56+09:00/debian_10.json integration/results/2021-08-11T01:57:57+09:00/debian_10.json
*** integration/results/2021-08-11T01:57:56+09:00/debian_10.json	2021-08-13 15:03:08.985173963 +0900
--- integration/results/2021-08-11T01:57:57+09:00/debian_10.json	2021-08-13 15:04:51.321315418 +0900
***************
*** 32,40 ****
          "172.17.0.1",
          "172.20.0.1"
      ],
!     "reportedAt": "2021-08-13T15:01:13.786994866+09:00",
      "reportedVersion": "v0.15.13",
!     "reportedRevision": "build-20210813_145815_d65421c",
      "reportedBy": "lize",
      "errors": [],
      "warnings": [],
--- 32,40 ----
          "172.17.0.1",
          "172.20.0.1"
      ],
!     "reportedAt": "2021-08-13T15:04:21.144451039+09:00",
      "reportedVersion": "v0.15.13",
!     "reportedRevision": "build-20210813_145848_b5c5568",
      "reportedBy": "lize",
      "errors": [],
      "warnings": [],
***************
*** 50229,50235 ****
              "ovalDict": {
                  "Name": "ovalDict",
                  "Type": "sqlite3",
!                 "SQLite3Path": "/home/mainek00n/github/github.com/MaineK00n/vuls/oval.master.sqlite3",
                  "DebugSQL": false
              },
              "gost": {
--- 50229,50235 ----
              "ovalDict": {
                  "Name": "ovalDict",
                  "Type": "sqlite3",
!                 "SQLite3Path": "/home/mainek00n/github/github.com/MaineK00n/vuls/oval.newmodel.sqlite3",
                  "DebugSQL": false
              },
              "gost": {
diff '--color=auto' -c integration/results/2021-08-11T01:57:56+09:00/oracle.json integration/results/2021-08-11T01:57:57+09:00/oracle.json
*** integration/results/2021-08-11T01:57:56+09:00/oracle.json	2021-08-13 15:03:09.045176586 +0900
--- integration/results/2021-08-11T01:57:57+09:00/oracle.json	2021-08-13 15:04:51.397318262 +0900
***************
*** 28,36 ****
      "scannedIpv4Addrs": [
          "172.27.0.1"
      ],
!     "reportedAt": "2021-08-13T15:01:13.786994866+09:00",
      "reportedVersion": "v0.15.13",
!     "reportedRevision": "build-20210813_145815_d65421c",
      "reportedBy": "lize",
      "errors": [],
      "warnings": [],
--- 28,36 ----
      "scannedIpv4Addrs": [
          "172.27.0.1"
      ],
!     "reportedAt": "2021-08-13T15:04:21.144451039+09:00",
      "reportedVersion": "v0.15.13",
!     "reportedRevision": "build-20210813_145848_b5c5568",
      "reportedBy": "lize",
      "errors": [],
      "warnings": [],
***************
*** 11760,11766 ****
              "ovalDict": {
                  "Name": "ovalDict",
                  "Type": "sqlite3",
!                 "SQLite3Path": "/home/mainek00n/github/github.com/MaineK00n/vuls/oval.master.sqlite3",
                  "DebugSQL": false
              },
              "gost": {
--- 11760,11766 ----
              "ovalDict": {
                  "Name": "ovalDict",
                  "Type": "sqlite3",
!                 "SQLite3Path": "/home/mainek00n/github/github.com/MaineK00n/vuls/oval.newmodel.sqlite3",
                  "DebugSQL": false
              },
              "gost": {
diff '--color=auto' -c integration/results/2021-08-11T01:57:56+09:00/rhel_71.json integration/results/2021-08-11T01:57:57+09:00/rhel_71.json
*** integration/results/2021-08-11T01:57:56+09:00/rhel_71.json	2021-08-13 15:03:09.453194407 +0900
--- integration/results/2021-08-11T01:57:57+09:00/rhel_71.json	2021-08-13 15:04:51.633327095 +0900
***************
*** 32,40 ****
          "172.17.0.1",
          "172.20.0.1"
      ],
!     "reportedAt": "2021-08-13T15:01:13.786994866+09:00",
      "reportedVersion": "v0.15.13",
!     "reportedRevision": "build-20210813_145815_d65421c",
      "reportedBy": "lize",
      "errors": [],
      "warnings": [],
--- 32,40 ----
          "172.17.0.1",
          "172.20.0.1"
      ],
!     "reportedAt": "2021-08-13T15:04:21.144451039+09:00",
      "reportedVersion": "v0.15.13",
!     "reportedRevision": "build-20210813_145848_b5c5568",
      "reportedBy": "lize",
      "errors": [],
      "warnings": [],
***************
*** 164532,164553 ****
              ],
              "affectedPackages": [
                  {
-                     "name": "dracut",
-                     "fixedIn": "0:033-502.el7_4.1"
-                 },
-                 {
-                     "name": "dracut-config-generic",
-                     "fixedIn": "0:033-502.el7_4.1"
-                 },
-                 {
-                     "name": "dracut-config-rescue",
-                     "fixedIn": "0:033-502.el7_4.1"
-                 },
-                 {
-                     "name": "dracut-network",
-                     "fixedIn": "0:033-502.el7_4.1"
-                 },
-                 {
                      "name": "kernel",
                      "notFixedYet": true,
                      "fixState": "Affected"
--- 164532,164537 ----
***************
*** 167538,167559 ****
              ],
              "affectedPackages": [
                  {
-                     "name": "dracut",
-                     "fixedIn": "0:033-502.el7_4.1"
-                 },
-                 {
-                     "name": "dracut-config-generic",
-                     "fixedIn": "0:033-502.el7_4.1"
-                 },
-                 {
-                     "name": "dracut-config-rescue",
-                     "fixedIn": "0:033-502.el7_4.1"
-                 },
-                 {
-                     "name": "dracut-network",
-                     "fixedIn": "0:033-502.el7_4.1"
-                 },
-                 {
                      "name": "kernel",
                      "fixedIn": "0:3.10.0-862.el7"
                  },
--- 167522,167527 ----
***************
*** 172360,172381 ****
              ],
              "affectedPackages": [
                  {
-                     "name": "dracut",
-                     "fixedIn": "0:033-502.el7_4.1"
-                 },
-                 {
-                     "name": "dracut-config-generic",
-                     "fixedIn": "0:033-502.el7_4.1"
-                 },
-                 {
-                     "name": "dracut-config-rescue",
-                     "fixedIn": "0:033-502.el7_4.1"
-                 },
-                 {
-                     "name": "dracut-network",
-                     "fixedIn": "0:033-502.el7_4.1"
-                 },
-                 {
                      "name": "kernel",
                      "fixedIn": "0:3.10.0-862.el7"
                  },
--- 172328,172333 ----
***************
*** 174995,175016 ****
              ],
              "affectedPackages": [
                  {
-                     "name": "dracut",
-                     "fixedIn": "0:033-502.el7_4.1"
-                 },
-                 {
-                     "name": "dracut-config-generic",
-                     "fixedIn": "0:033-502.el7_4.1"
-                 },
-                 {
-                     "name": "dracut-config-rescue",
-                     "fixedIn": "0:033-502.el7_4.1"
-                 },
-                 {
-                     "name": "dracut-network",
-                     "fixedIn": "0:033-502.el7_4.1"
-                 },
-                 {
                      "name": "kernel",
                      "fixedIn": "0:3.10.0-862.el7"
                  },
--- 174947,174952 ----
***************
*** 177221,177242 ****
              ],
              "affectedPackages": [
                  {
-                     "name": "dracut",
-                     "fixedIn": "0:033-502.el7_4.1"
-                 },
-                 {
-                     "name": "dracut-config-generic",
-                     "fixedIn": "0:033-502.el7_4.1"
-                 },
-                 {
-                     "name": "dracut-config-rescue",
-                     "fixedIn": "0:033-502.el7_4.1"
-                 },
-                 {
-                     "name": "dracut-network",
-                     "fixedIn": "0:033-502.el7_4.1"
-                 },
-                 {
                      "name": "kernel",
                      "fixedIn": "0:3.10.0-862.el7"
                  },
--- 177157,177162 ----
***************
*** 182224,182245 ****
              ],
              "affectedPackages": [
                  {
-                     "name": "dracut",
-                     "fixedIn": "0:033-502.el7_4.1"
-                 },
-                 {
-                     "name": "dracut-config-generic",
-                     "fixedIn": "0:033-502.el7_4.1"
-                 },
-                 {
-                     "name": "dracut-config-rescue",
-                     "fixedIn": "0:033-502.el7_4.1"
-                 },
-                 {
-                     "name": "dracut-network",
-                     "fixedIn": "0:033-502.el7_4.1"
-                 },
-                 {
                      "name": "kernel",
                      "fixedIn": "0:3.10.0-862.el7"
                  },
--- 182144,182149 ----
***************
*** 194482,194495 ****
                  {
                      "name": "nss-util",
                      "fixedIn": "0:3.44.0-3.el7"
-                 },
-                 {
-                     "name": "openssl",
-                     "fixedIn": "1:1.0.2k-16.el7"
-                 },
-                 {
-                     "name": "openssl-libs",
-                     "fixedIn": "1:1.0.2k-16.el7"
                  }
              ],
              "distroAdvisories": [
--- 194386,194391 ----
***************
*** 211089,211114 ****
              ],
              "affectedPackages": [
                  {
-                     "name": "NetworkManager",
-                     "fixedIn": "1:1.12.0-8.el7_6"
-                 },
-                 {
-                     "name": "NetworkManager-config-server",
-                     "fixedIn": "1:1.12.0-8.el7_6"
-                 },
-                 {
-                     "name": "NetworkManager-libnm",
-                     "fixedIn": "1:1.12.0-8.el7_6"
-                 },
-                 {
-                     "name": "NetworkManager-team",
-                     "fixedIn": "1:1.12.0-8.el7_6"
-                 },
-                 {
-                     "name": "NetworkManager-tui",
-                     "fixedIn": "1:1.12.0-8.el7_6"
-                 },
-                 {
                      "name": "libgudev1",
                      "fixedIn": "0:219-62.el7_6.2"
                  },
--- 210985,210990 ----
***************
*** 211366,211391 ****
              ],
              "affectedPackages": [
                  {
-                     "name": "NetworkManager",
-                     "fixedIn": "1:1.12.0-8.el7_6"
-                 },
-                 {
-                     "name": "NetworkManager-config-server",
-                     "fixedIn": "1:1.12.0-8.el7_6"
-                 },
-                 {
-                     "name": "NetworkManager-libnm",
-                     "fixedIn": "1:1.12.0-8.el7_6"
-                 },
-                 {
-                     "name": "NetworkManager-team",
-                     "fixedIn": "1:1.12.0-8.el7_6"
-                 },
-                 {
-                     "name": "NetworkManager-tui",
-                     "fixedIn": "1:1.12.0-8.el7_6"
-                 },
-                 {
                      "name": "libgudev1",
                      "fixedIn": "0:219-62.el7_6.2"
                  },
--- 211242,211247 ----
***************
*** 233030,233051 ****
              ],
              "affectedPackages": [
                  {
-                     "name": "dracut",
-                     "fixedIn": "0:033-502.el7_4.1"
-                 },
-                 {
-                     "name": "dracut-config-generic",
-                     "fixedIn": "0:033-502.el7_4.1"
-                 },
-                 {
-                     "name": "dracut-config-rescue",
-                     "fixedIn": "0:033-502.el7_4.1"
-                 },
-                 {
-                     "name": "dracut-network",
-                     "fixedIn": "0:033-502.el7_4.1"
-                 },
-                 {
                      "name": "kernel",
                      "fixedIn": "0:3.10.0-862.el7"
                  },
--- 232886,232891 ----
***************
*** 234620,234641 ****
              ],
              "affectedPackages": [
                  {
-                     "name": "dracut",
-                     "fixedIn": "0:033-502.el7_4.1"
-                 },
-                 {
-                     "name": "dracut-config-generic",
-                     "fixedIn": "0:033-502.el7_4.1"
-                 },
-                 {
-                     "name": "dracut-config-rescue",
-                     "fixedIn": "0:033-502.el7_4.1"
-                 },
-                 {
-                     "name": "dracut-network",
-                     "fixedIn": "0:033-502.el7_4.1"
-                 },
-                 {
                      "name": "kernel",
                      "fixedIn": "0:3.10.0-862.el7"
                  },
--- 234460,234465 ----
***************
*** 280530,280543 ****
                  {
                      "name": "nss-util",
                      "fixedIn": "0:3.44.0-3.el7"
-                 },
-                 {
-                     "name": "openssl",
-                     "fixedIn": "1:1.0.2k-16.el7"
-                 },
-                 {
-                     "name": "openssl-libs",
-                     "fixedIn": "1:1.0.2k-16.el7"
                  }
              ],
              "distroAdvisories": [
--- 280354,280359 ----
***************
*** 344939,344945 ****
              "ovalDict": {
                  "Name": "ovalDict",
                  "Type": "sqlite3",
!                 "SQLite3Path": "/home/mainek00n/github/github.com/MaineK00n/vuls/oval.master.sqlite3",
                  "DebugSQL": false
              },
              "gost": {
--- 344755,344761 ----
              "ovalDict": {
                  "Name": "ovalDict",
                  "Type": "sqlite3",
!                 "SQLite3Path": "/home/mainek00n/github/github.com/MaineK00n/vuls/oval.newmodel.sqlite3",
                  "DebugSQL": false
              },
              "gost": {
diff '--color=auto' -c integration/results/2021-08-11T01:57:56+09:00/rhel_8.json integration/results/2021-08-11T01:57:57+09:00/rhel_8.json
*** integration/results/2021-08-11T01:57:56+09:00/rhel_8.json	2021-08-13 15:03:09.529197727 +0900
--- integration/results/2021-08-11T01:57:57+09:00/rhel_8.json	2021-08-13 15:04:51.697329490 +0900
***************
*** 32,40 ****
          "172.17.0.1",
          "172.20.0.1"
      ],
!     "reportedAt": "2021-08-13T15:01:13.786994866+09:00",
      "reportedVersion": "v0.15.13",
!     "reportedRevision": "build-20210813_145815_d65421c",
      "reportedBy": "lize",
      "errors": [],
      "warnings": [],
--- 32,40 ----
          "172.17.0.1",
          "172.20.0.1"
      ],
!     "reportedAt": "2021-08-13T15:04:21.144451039+09:00",
      "reportedVersion": "v0.15.13",
!     "reportedRevision": "build-20210813_145848_b5c5568",
      "reportedBy": "lize",
      "errors": [],
      "warnings": [],
***************
*** 38495,38501 ****
              "ovalDict": {
                  "Name": "ovalDict",
                  "Type": "sqlite3",
!                 "SQLite3Path": "/home/mainek00n/github/github.com/MaineK00n/vuls/oval.master.sqlite3",
                  "DebugSQL": false
              },
              "gost": {
--- 38495,38501 ----
              "ovalDict": {
                  "Name": "ovalDict",
                  "Type": "sqlite3",
!                 "SQLite3Path": "/home/mainek00n/github/github.com/MaineK00n/vuls/oval.newmodel.sqlite3",
                  "DebugSQL": false
              },
              "gost": {
diff '--color=auto' -c integration/results/2021-08-11T01:57:56+09:00/ubuntu_1804.json integration/results/2021-08-11T01:57:57+09:00/ubuntu_1804.json
*** integration/results/2021-08-11T01:57:56+09:00/ubuntu_1804.json	2021-08-13 15:03:09.545198426 +0900
--- integration/results/2021-08-11T01:57:57+09:00/ubuntu_1804.json	2021-08-13 15:04:51.717330238 +0900
***************
*** 32,40 ****
          "172.17.0.1",
          "172.20.0.1"
      ],
!     "reportedAt": "2021-08-13T15:01:13.786994866+09:00",
      "reportedVersion": "v0.15.13",
!     "reportedRevision": "build-20210813_145815_d65421c",
      "reportedBy": "lize",
      "errors": [],
      "warnings": [],
--- 32,40 ----
          "172.17.0.1",
          "172.20.0.1"
      ],
!     "reportedAt": "2021-08-13T15:04:21.144451039+09:00",
      "reportedVersion": "v0.15.13",
!     "reportedRevision": "build-20210813_145848_b5c5568",
      "reportedBy": "lize",
      "errors": [],
      "warnings": [],
***************
*** 32130,32136 ****
              "ovalDict": {
                  "Name": "ovalDict",
                  "Type": "sqlite3",
!                 "SQLite3Path": "/home/mainek00n/github/github.com/MaineK00n/vuls/oval.master.sqlite3",
                  "DebugSQL": false
              },
              "gost": {
--- 32130,32136 ----
              "ovalDict": {
                  "Name": "ovalDict",
                  "Type": "sqlite3",
!                 "SQLite3Path": "/home/mainek00n/github/github.com/MaineK00n/vuls/oval.newmodel.sqlite3",
                  "DebugSQL": false
              },
              "gost": {
diff '--color=auto' -c integration/results/2021-08-11T01:57:56+09:00/ubuntu_2004.json integration/results/2021-08-11T01:57:57+09:00/ubuntu_2004.json
*** integration/results/2021-08-11T01:57:56+09:00/ubuntu_2004.json	2021-08-13 15:03:09.565199300 +0900
--- integration/results/2021-08-11T01:57:57+09:00/ubuntu_2004.json	2021-08-13 15:04:51.737330987 +0900
***************
*** 32,40 ****
          "172.17.0.1",
          "172.20.0.1"
      ],
!     "reportedAt": "2021-08-13T15:01:13.786994866+09:00",
      "reportedVersion": "v0.15.13",
!     "reportedRevision": "build-20210813_145815_d65421c",
      "reportedBy": "lize",
      "errors": [],
      "warnings": [],
--- 32,40 ----
          "172.17.0.1",
          "172.20.0.1"
      ],
!     "reportedAt": "2021-08-13T15:04:21.144451039+09:00",
      "reportedVersion": "v0.15.13",
!     "reportedRevision": "build-20210813_145848_b5c5568",
      "reportedBy": "lize",
      "errors": [],
      "warnings": [],
***************
*** 32942,32948 ****
              "ovalDict": {
                  "Name": "ovalDict",
                  "Type": "sqlite3",
!                 "SQLite3Path": "/home/mainek00n/github/github.com/MaineK00n/vuls/oval.master.sqlite3",
                  "DebugSQL": false
              },
              "gost": {
--- 32942,32948 ----
              "ovalDict": {
                  "Name": "ovalDict",
                  "Type": "sqlite3",
!                 "SQLite3Path": "/home/mainek00n/github/github.com/MaineK00n/vuls/oval.newmodel.sqlite3",
                  "DebugSQL": false
              },
              "gost": {

@MaineK00n
Copy link
Collaborator Author

The diffs around 164532 and 164553 in integration/results/2021-08-11T01:57:56+09:00/rhel_71.json are the affectedPackages part of CVE-2017-5754.

"CVE-2017-5754": {
            "cveID": "CVE-2017-5754",
            "confidences": [
                {
                    "score": 100,
                    "detectionMethod": "OvalMatch"
                }
            ],
            "affectedPackages": [
                {
                    "name": "dracut",
                    "fixedIn": "0:033-502.el7_4.1"
                },
                {
                    "name": "dracut-config-generic",
                    "fixedIn": "0:033-502.el7_4.1"
                },
                {
                    "name": "dracut-config-rescue",
                    "fixedIn": "0:033-502.el7_4.1"
                },
                {
                    "name": "dracut-network",
                    "fixedIn": "0:033-502.el7_4.1"
                },
                {
                    "name": "kernel",
                    "notFixedYet": true,
                    "fixState": "Affected"
                },
                {
                    "name": "kernel-tools",
                    "fixedIn": "0:3.10.0-862.el7"
                },
                {
                    "name": "kernel-tools-libs",
                    "fixedIn": "0:3.10.0-862.el7"
                }
            ],

Check CVE-2017-5754's AffectedPackages in goval-dictionary.
There is no package named dracut in the AffectedPacks of the Definition that contains CVE-2017-5754.

$ goval-dictionary select --by-cveid redhat 7 CVE-2017-5754
[]models.Definition{
  models.Definition{
    DefinitionID: "oval:com.redhat.rhsa:def:20180016",
    Title:        "RHSA-2018:0016: kernel-rt security update (Important)",
    Advisory:     models.Advisory{
      Cves:         []models.Cve{
        models.Cve{
          CveID:      "CVE-2017-5754",
        },
      },
    AffectedPacks: []models.Package{
      models.Package{
        Name:            "kernel-rt",
        Version:         "0:3.10.0-693.11.1.rt56.639.el7",
      },
      models.Package{
        Name:            "kernel-rt-debug",
        Version:         "0:3.10.0-693.11.1.rt56.639.el7",
      },
      models.Package{
        Name:            "kernel-rt-debug-devel",
        Version:         "0:3.10.0-693.11.1.rt56.639.el7",
      },
      models.Package{
        Name:            "kernel-rt-debug-kvm",
        Version:         "0:3.10.0-693.11.1.rt56.639.el7",
      },
      models.Package{
        Name:            "kernel-rt-devel",
        Version:         "0:3.10.0-693.11.1.rt56.639.el7",
      },
      models.Package{
        Name:            "kernel-rt-doc",
        Version:         "0:3.10.0-693.11.1.rt56.639.el7",
      },
      models.Package{
        Name:            "kernel-rt-kvm",
        Version:         "0:3.10.0-693.11.1.rt56.639.el7",
      },
      models.Package{
        Name:            "kernel-rt-trace",
        Version:         "0:3.10.0-693.11.1.rt56.639.el7",
      },
      models.Package{
        Name:            "kernel-rt-trace-devel",
        Version:         "0:3.10.0-693.11.1.rt56.639.el7",
      },
      models.Package{
        Name:            "kernel-rt-trace-kvm",
        Version:         "0:3.10.0-693.11.1.rt56.639.el7",
      },
    },
  },
  models.Definition{
    DefinitionID: "oval:com.redhat.rhsa:def:20181062",
    Title:        "RHSA-2018:1062: kernel security, bug fix, and enhancement update (Important)",
    Advisory:     models.Advisory{
      Cves:         []models.Cve{
        models.Cve{
          CveID:      "CVE-2017-5754",
        },
      },
    },
    AffectedPacks: []models.Package{
      models.Package{
        Name:            "kernel",
        Version:         "0:3.10.0-862.el7",
      },
      models.Package{
        Name:            "kernel-abi-whitelists",
        Version:         "0:3.10.0-862.el7",
      },
      models.Package{
        Name:            "kernel-bootwrapper",
        Version:         "0:3.10.0-862.el7",
      },
      models.Package{
        Name:            "kernel-debug",
        Version:         "0:3.10.0-862.el7",
      },
      models.Package{
        Name:            "kernel-debug-devel",
        Version:         "0:3.10.0-862.el7",
      },
      models.Package{
        Name:            "kernel-devel",
        Version:         "0:3.10.0-862.el7",
      },
      models.Package{
        Name:            "kernel-doc",
        Version:         "0:3.10.0-862.el7",
      },
      models.Package{
        Name:            "kernel-headers",
        Version:         "0:3.10.0-862.el7",
      },
      models.Package{
        Name:            "kernel-kdump",
        Version:         "0:3.10.0-862.el7",
      },
      models.Package{
        Name:            "kernel-kdump-devel",
        Version:         "0:3.10.0-862.el7",
      },
      models.Package{
        Name:            "kernel-tools",
        Version:         "0:3.10.0-862.el7",
      },
      models.Package{
        Name:            "kernel-tools-libs",
        Version:         "0:3.10.0-862.el7",
      },
      models.Package{
        Name:            "kernel-tools-libs-devel",
        Version:         "0:3.10.0-862.el7",
      },
      models.Package{
        Name:            "perf",
        Version:         "0:3.10.0-862.el7",
      },
      models.Package{
        Name:            "python-perf",
        Version:         "0:3.10.0-862.el7",
      },
    },
  },
}

Next, I checked why the package dracut was included in affectedPackages.
The following code is related to affectedPackages in OVAL.
In this section, the process is to add the packages of vinfo.AffectedPackages to defPacks.binpkgFixstat and then return them to vinfo.AffectedPackages.
However, since the whole thing is looped through defPacks.def.Advisory.Cves, this part that is written directly to defPacks depends on the order of defPacks.def.Advisory.Cves.
I found that this is the source of the difference.

vuls/oval/redhat.go

Lines 135 to 149 in d65421c

for _, pack := range vinfo.AffectedPackages {
if stat, ok := defPacks.binpkgFixstat[pack.Name]; !ok {
defPacks.binpkgFixstat[pack.Name] = fixStat{
notFixedYet: pack.NotFixedYet,
fixedIn: pack.FixedIn,
}
} else if stat.notFixedYet {
defPacks.binpkgFixstat[pack.Name] = fixStat{
notFixedYet: true,
fixedIn: pack.FixedIn,
}
}
}
vinfo.AffectedPackages = defPacks.toPackStatuses()
vinfo.AffectedPackages.Sort()

Verification logs.
The package dracut has been added to all defPacks.binpkgFixstat since CVE-2017-5715.

  • master
defPacks.def.DefinitionID = oval:com.redhat.rhsa:def:20181062, cve.CveID = CVE-2016-3672, defPacks.binpkgFixstat = map[string]oval.fixStat{\"kernel\":oval.fixStat{notFixedYet:false, fixedIn:\"0:3.10.0-862.el7\", isSrcPack:false, srcPackName:\"\"}, \"kernel-tools\":oval.fixStat{notFixedYet:false, fixedIn:\"0:3.10.0-862.el7\", isSrcPack:false, srcPackName:\"\"}, \"kernel-tools-libs\":oval.fixStat{notFixedYet:false, fixedIn:\"0:3.10.0-862.el7\", isSrcPack:false, srcPackName:\"\"}} 
defPacks.def.DefinitionID = oval:com.redhat.rhsa:def:20181062, cve.CveID = CVE-2016-7913, defPacks.binpkgFixstat = map[string]oval.fixStat{\"kernel\":oval.fixStat{notFixedYet:false, fixedIn:\"0:3.10.0-862.el7\", isSrcPack:false, srcPackName:\"\"}, \"kernel-tools\":oval.fixStat{notFixedYet:false, fixedIn:\"0:3.10.0-862.el7\", isSrcPack:false, srcPackName:\"\"}, \"kernel-tools-libs\":oval.fixStat{notFixedYet:false, fixedIn:\"0:3.10.0-862.el7\", isSrcPack:false, srcPackName:\"\"}} 
defPacks.def.DefinitionID = oval:com.redhat.rhsa:def:20181062, cve.CveID = CVE-2016-8633, defPacks.binpkgFixstat = map[string]oval.fixStat{\"kernel\":oval.fixStat{notFixedYet:false, fixedIn:\"0:3.10.0-862.el7\", isSrcPack:false, srcPackName:\"\"}, \"kernel-tools\":oval.fixStat{notFixedYet:false, fixedIn:\"0:3.10.0-862.el7\", isSrcPack:false, srcPackName:\"\"}, \"kernel-tools-libs\":oval.fixStat{notFixedYet:false, fixedIn:\"0:3.10.0-862.el7\", isSrcPack:false, srcPackName:\"\"}} 
defPacks.def.DefinitionID = oval:com.redhat.rhsa:def:20181062, cve.CveID = CVE-2017-1000252, defPacks.binpkgFixstat = map[string]oval.fixStat{\"kernel\":oval.fixStat{notFixedYet:false, fixedIn:\"0:3.10.0-862.el7\", isSrcPack:false, srcPackName:\"\"}, \"kernel-tools\":oval.fixStat{notFixedYet:false, fixedIn:\"0:3.10.0-862.el7\", isSrcPack:false, srcPackName:\"\"}, \"kernel-tools-libs\":oval.fixStat{notFixedYet:false, fixedIn:\"0:3.10.0-862.el7\", isSrcPack:false, srcPackName:\"\"}} 
defPacks.def.DefinitionID = oval:com.redhat.rhsa:def:20181062, cve.CveID = CVE-2017-1000407, defPacks.binpkgFixstat = map[string]oval.fixStat{\"kernel\":oval.fixStat{notFixedYet:false, fixedIn:\"0:3.10.0-862.el7\", isSrcPack:false, srcPackName:\"\"}, \"kernel-tools\":oval.fixStat{notFixedYet:false, fixedIn:\"0:3.10.0-862.el7\", isSrcPack:false, srcPackName:\"\"}, \"kernel-tools-libs\":oval.fixStat{notFixedYet:false, fixedIn:\"0:3.10.0-862.el7\", isSrcPack:false, srcPackName:\"\"}} 
defPacks.def.DefinitionID = oval:com.redhat.rhsa:def:20181062, cve.CveID = CVE-2017-1000410, defPacks.binpkgFixstat = map[string]oval.fixStat{\"kernel\":oval.fixStat{notFixedYet:false, fixedIn:\"0:3.10.0-862.el7\", isSrcPack:false, srcPackName:\"\"}, \"kernel-tools\":oval.fixStat{notFixedYet:false, fixedIn:\"0:3.10.0-862.el7\", isSrcPack:false, srcPackName:\"\"}, \"kernel-tools-libs\":oval.fixStat{notFixedYet:false, fixedIn:\"0:3.10.0-862.el7\", isSrcPack:false, srcPackName:\"\"}} 
defPacks.def.DefinitionID = oval:com.redhat.rhsa:def:20181062, cve.CveID = CVE-2017-12154, defPacks.binpkgFixstat = map[string]oval.fixStat{\"kernel\":oval.fixStat{notFixedYet:false, fixedIn:\"0:3.10.0-862.el7\", isSrcPack:false, srcPackName:\"\"}, \"kernel-tools\":oval.fixStat{notFixedYet:false, fixedIn:\"0:3.10.0-862.el7\", isSrcPack:false, srcPackName:\"\"}, \"kernel-tools-libs\":oval.fixStat{notFixedYet:false, fixedIn:\"0:3.10.0-862.el7\", isSrcPack:false, srcPackName:\"\"}} 
defPacks.def.DefinitionID = oval:com.redhat.rhsa:def:20181062, cve.CveID = CVE-2017-12190, defPacks.binpkgFixstat = map[string]oval.fixStat{\"kernel\":oval.fixStat{notFixedYet:false, fixedIn:\"0:3.10.0-862.el7\", isSrcPack:false, srcPackName:\"\"}, \"kernel-tools\":oval.fixStat{notFixedYet:false, fixedIn:\"0:3.10.0-862.el7\", isSrcPack:false, srcPackName:\"\"}, \"kernel-tools-libs\":oval.fixStat{notFixedYet:false, fixedIn:\"0:3.10.0-862.el7\", isSrcPack:false, srcPackName:\"\"}} 
defPacks.def.DefinitionID = oval:com.redhat.rhsa:def:20181062, cve.CveID = CVE-2017-13166, defPacks.binpkgFixstat = map[string]oval.fixStat{\"kernel\":oval.fixStat{notFixedYet:false, fixedIn:\"0:3.10.0-862.el7\", isSrcPack:false, srcPackName:\"\"}, \"kernel-tools\":oval.fixStat{notFixedYet:false, fixedIn:\"0:3.10.0-862.el7\", isSrcPack:false, srcPackName:\"\"}, \"kernel-tools-libs\":oval.fixStat{notFixedYet:false, fixedIn:\"0:3.10.0-862.el7\", isSrcPack:false, srcPackName:\"\"}} 
defPacks.def.DefinitionID = oval:com.redhat.rhsa:def:20181062, cve.CveID = CVE-2017-13305, defPacks.binpkgFixstat = map[string]oval.fixStat{\"kernel\":oval.fixStat{notFixedYet:false, fixedIn:\"0:3.10.0-862.el7\", isSrcPack:false, srcPackName:\"\"}, \"kernel-tools\":oval.fixStat{notFixedYet:false, fixedIn:\"0:3.10.0-862.el7\", isSrcPack:false, srcPackName:\"\"}, \"kernel-tools-libs\":oval.fixStat{notFixedYet:false, fixedIn:\"0:3.10.0-862.el7\", isSrcPack:false, srcPackName:\"\"}} 
defPacks.def.DefinitionID = oval:com.redhat.rhsa:def:20181062, cve.CveID = CVE-2017-14140, defPacks.binpkgFixstat = map[string]oval.fixStat{\"kernel\":oval.fixStat{notFixedYet:false, fixedIn:\"0:3.10.0-862.el7\", isSrcPack:false, srcPackName:\"\"}, \"kernel-tools\":oval.fixStat{notFixedYet:false, fixedIn:\"0:3.10.0-862.el7\", isSrcPack:false, srcPackName:\"\"}, \"kernel-tools-libs\":oval.fixStat{notFixedYet:false, fixedIn:\"0:3.10.0-862.el7\", isSrcPack:false, srcPackName:\"\"}} 
defPacks.def.DefinitionID = oval:com.redhat.rhsa:def:20181062, cve.CveID = CVE-2017-15116, defPacks.binpkgFixstat = map[string]oval.fixStat{\"kernel\":oval.fixStat{notFixedYet:false, fixedIn:\"0:3.10.0-862.el7\", isSrcPack:false, srcPackName:\"\"}, \"kernel-tools\":oval.fixStat{notFixedYet:false, fixedIn:\"0:3.10.0-862.el7\", isSrcPack:false, srcPackName:\"\"}, \"kernel-tools-libs\":oval.fixStat{notFixedYet:false, fixedIn:\"0:3.10.0-862.el7\", isSrcPack:false, srcPackName:\"\"}} 
defPacks.def.DefinitionID = oval:com.redhat.rhsa:def:20181062, cve.CveID = CVE-2017-15121, defPacks.binpkgFixstat = map[string]oval.fixStat{\"kernel\":oval.fixStat{notFixedYet:false, fixedIn:\"0:3.10.0-862.el7\", isSrcPack:false, srcPackName:\"\"}, \"kernel-tools\":oval.fixStat{notFixedYet:false, fixedIn:\"0:3.10.0-862.el7\", isSrcPack:false, srcPackName:\"\"}, \"kernel-tools-libs\":oval.fixStat{notFixedYet:false, fixedIn:\"0:3.10.0-862.el7\", isSrcPack:false, srcPackName:\"\"}} 
defPacks.def.DefinitionID = oval:com.redhat.rhsa:def:20181062, cve.CveID = CVE-2017-15126, defPacks.binpkgFixstat = map[string]oval.fixStat{\"kernel\":oval.fixStat{notFixedYet:false, fixedIn:\"0:3.10.0-862.el7\", isSrcPack:false, srcPackName:\"\"}, \"kernel-tools\":oval.fixStat{notFixedYet:false, fixedIn:\"0:3.10.0-862.el7\", isSrcPack:false, srcPackName:\"\"}, \"kernel-tools-libs\":oval.fixStat{notFixedYet:false, fixedIn:\"0:3.10.0-862.el7\", isSrcPack:false, srcPackName:\"\"}} 
defPacks.def.DefinitionID = oval:com.redhat.rhsa:def:20181062, cve.CveID = CVE-2017-15127, defPacks.binpkgFixstat = map[string]oval.fixStat{\"kernel\":oval.fixStat{notFixedYet:false, fixedIn:\"0:3.10.0-862.el7\", isSrcPack:false, srcPackName:\"\"}, \"kernel-tools\":oval.fixStat{notFixedYet:false, fixedIn:\"0:3.10.0-862.el7\", isSrcPack:false, srcPackName:\"\"}, \"kernel-tools-libs\":oval.fixStat{notFixedYet:false, fixedIn:\"0:3.10.0-862.el7\", isSrcPack:false, srcPackName:\"\"}} 
defPacks.def.DefinitionID = oval:com.redhat.rhsa:def:20181062, cve.CveID = CVE-2017-15129, defPacks.binpkgFixstat = map[string]oval.fixStat{\"kernel\":oval.fixStat{notFixedYet:false, fixedIn:\"0:3.10.0-862.el7\", isSrcPack:false, srcPackName:\"\"}, \"kernel-tools\":oval.fixStat{notFixedYet:false, fixedIn:\"0:3.10.0-862.el7\", isSrcPack:false, srcPackName:\"\"}, \"kernel-tools-libs\":oval.fixStat{notFixedYet:false, fixedIn:\"0:3.10.0-862.el7\", isSrcPack:false, srcPackName:\"\"}} 
defPacks.def.DefinitionID = oval:com.redhat.rhsa:def:20181062, cve.CveID = CVE-2017-15265, defPacks.binpkgFixstat = map[string]oval.fixStat{\"kernel\":oval.fixStat{notFixedYet:false, fixedIn:\"0:3.10.0-862.el7\", isSrcPack:false, srcPackName:\"\"}, \"kernel-tools\":oval.fixStat{notFixedYet:false, fixedIn:\"0:3.10.0-862.el7\", isSrcPack:false, srcPackName:\"\"}, \"kernel-tools-libs\":oval.fixStat{notFixedYet:false, fixedIn:\"0:3.10.0-862.el7\", isSrcPack:false, srcPackName:\"\"}} 
defPacks.def.DefinitionID = oval:com.redhat.rhsa:def:20181062, cve.CveID = CVE-2017-15274, defPacks.binpkgFixstat = map[string]oval.fixStat{\"kernel\":oval.fixStat{notFixedYet:false, fixedIn:\"0:3.10.0-862.el7\", isSrcPack:false, srcPackName:\"\"}, \"kernel-tools\":oval.fixStat{notFixedYet:false, fixedIn:\"0:3.10.0-862.el7\", isSrcPack:false, srcPackName:\"\"}, \"kernel-tools-libs\":oval.fixStat{notFixedYet:false, fixedIn:\"0:3.10.0-862.el7\", isSrcPack:false, srcPackName:\"\"}} 
defPacks.def.DefinitionID = oval:com.redhat.rhsa:def:20181062, cve.CveID = CVE-2017-17448, defPacks.binpkgFixstat = map[string]oval.fixStat{\"kernel\":oval.fixStat{notFixedYet:false, fixedIn:\"0:3.10.0-862.el7\", isSrcPack:false, srcPackName:\"\"}, \"kernel-tools\":oval.fixStat{notFixedYet:false, fixedIn:\"0:3.10.0-862.el7\", isSrcPack:false, srcPackName:\"\"}, \"kernel-tools-libs\":oval.fixStat{notFixedYet:false, fixedIn:\"0:3.10.0-862.el7\", isSrcPack:false, srcPackName:\"\"}} 
defPacks.def.DefinitionID = oval:com.redhat.rhsa:def:20181062, cve.CveID = CVE-2017-17449, defPacks.binpkgFixstat = map[string]oval.fixStat{\"kernel\":oval.fixStat{notFixedYet:false, fixedIn:\"0:3.10.0-862.el7\", isSrcPack:false, srcPackName:\"\"}, \"kernel-tools\":oval.fixStat{notFixedYet:false, fixedIn:\"0:3.10.0-862.el7\", isSrcPack:false, srcPackName:\"\"}, \"kernel-tools-libs\":oval.fixStat{notFixedYet:false, fixedIn:\"0:3.10.0-862.el7\", isSrcPack:false, srcPackName:\"\"}} 
defPacks.def.DefinitionID = oval:com.redhat.rhsa:def:20181062, cve.CveID = CVE-2017-17558, defPacks.binpkgFixstat = map[string]oval.fixStat{\"kernel\":oval.fixStat{notFixedYet:false, fixedIn:\"0:3.10.0-862.el7\", isSrcPack:false, srcPackName:\"\"}, \"kernel-tools\":oval.fixStat{notFixedYet:false, fixedIn:\"0:3.10.0-862.el7\", isSrcPack:false, srcPackName:\"\"}, \"kernel-tools-libs\":oval.fixStat{notFixedYet:false, fixedIn:\"0:3.10.0-862.el7\", isSrcPack:false, srcPackName:\"\"}} 
defPacks.def.DefinitionID = oval:com.redhat.rhsa:def:20181062, cve.CveID = CVE-2017-18017, defPacks.binpkgFixstat = map[string]oval.fixStat{\"kernel\":oval.fixStat{notFixedYet:false, fixedIn:\"0:3.10.0-862.el7\", isSrcPack:false, srcPackName:\"\"}, \"kernel-tools\":oval.fixStat{notFixedYet:false, fixedIn:\"0:3.10.0-862.el7\", isSrcPack:false, srcPackName:\"\"}, \"kernel-tools-libs\":oval.fixStat{notFixedYet:false, fixedIn:\"0:3.10.0-862.el7\", isSrcPack:false, srcPackName:\"\"}} 
defPacks.def.DefinitionID = oval:com.redhat.rhsa:def:20181062, cve.CveID = CVE-2017-18203, defPacks.binpkgFixstat = map[string]oval.fixStat{\"kernel\":oval.fixStat{notFixedYet:false, fixedIn:\"0:3.10.0-862.el7\", isSrcPack:false, srcPackName:\"\"}, \"kernel-tools\":oval.fixStat{notFixedYet:false, fixedIn:\"0:3.10.0-862.el7\", isSrcPack:false, srcPackName:\"\"}, \"kernel-tools-libs\":oval.fixStat{notFixedYet:false, fixedIn:\"0:3.10.0-862.el7\", isSrcPack:false, srcPackName:\"\"}} 
defPacks.def.DefinitionID = oval:com.redhat.rhsa:def:20181062, cve.CveID = CVE-2017-18270, defPacks.binpkgFixstat = map[string]oval.fixStat{\"kernel\":oval.fixStat{notFixedYet:false, fixedIn:\"0:3.10.0-862.el7\", isSrcPack:false, srcPackName:\"\"}, \"kernel-tools\":oval.fixStat{notFixedYet:false, fixedIn:\"0:3.10.0-862.el7\", isSrcPack:false, srcPackName:\"\"}, \"kernel-tools-libs\":oval.fixStat{notFixedYet:false, fixedIn:\"0:3.10.0-862.el7\", isSrcPack:false, srcPackName:\"\"}} 
defPacks.def.DefinitionID = oval:com.redhat.rhsa:def:20181062, cve.CveID = CVE-2017-5715, defPacks.binpkgFixstat = map[string]oval.fixStat{\"dracut\":oval.fixStat{notFixedYet:false, fixedIn:\"0:033-502.el7_4.1\", isSrcPack:false, srcPackName:\"\"}, \"dracut-config-generic\":oval.fixStat{notFixedYet:false, fixedIn:\"0:033-502.el7_4.1\", isSrcPack:false, srcPackName:\"\"}, \"dracut-config-rescue\":oval.fixStat{notFixedYet:false, fixedIn:\"0:033-502.el7_4.1\", isSrcPack:false, srcPackName:\"\"}, \"dracut-network\":oval.fixStat{notFixedYet:false, fixedIn:\"0:033-502.el7_4.1\", isSrcPack:false, srcPackName:\"\"}, \"kernel\":oval.fixStat{notFixedYet:false, fixedIn:\"0:3.10.0-862.el7\", isSrcPack:false, srcPackName:\"\"}, \"kernel-tools\":oval.fixStat{notFixedYet:false, fixedIn:\"0:3.10.0-862.el7\", isSrcPack:false, srcPackName:\"\"}, \"kernel-tools-libs\":oval.fixStat{notFixedYet:false, fixedIn:\"0:3.10.0-862.el7\", isSrcPack:false, srcPackName:\"\"}} 
defPacks.def.DefinitionID = oval:com.redhat.rhsa:def:20181062, cve.CveID = CVE-2017-5754, defPacks.binpkgFixstat = map[string]oval.fixStat{\"dracut\":oval.fixStat{notFixedYet:false, fixedIn:\"0:033-502.el7_4.1\", isSrcPack:false, srcPackName:\"\"}, \"dracut-config-generic\":oval.fixStat{notFixedYet:false, fixedIn:\"0:033-502.el7_4.1\", isSrcPack:false, srcPackName:\"\"}, \"dracut-config-rescue\":oval.fixStat{notFixedYet:false, fixedIn:\"0:033-502.el7_4.1\", isSrcPack:false, srcPackName:\"\"}, \"dracut-network\":oval.fixStat{notFixedYet:false, fixedIn:\"0:033-502.el7_4.1\", isSrcPack:false, srcPackName:\"\"}, \"kernel\":oval.fixStat{notFixedYet:false, fixedIn:\"0:3.10.0-862.el7\", isSrcPack:false, srcPackName:\"\"}, \"kernel-tools\":oval.fixStat{notFixedYet:false, fixedIn:\"0:3.10.0-862.el7\", isSrcPack:false, srcPackName:\"\"}, \"kernel-tools-libs\":oval.fixStat{notFixedYet:false, fixedIn:\"0:3.10.0-862.el7\", isSrcPack:false, srcPackName:\"\"}} 
defPacks.def.DefinitionID = oval:com.redhat.rhsa:def:20181062, cve.CveID = CVE-2017-7294, defPacks.binpkgFixstat = map[string]oval.fixStat{\"dracut\":oval.fixStat{notFixedYet:false, fixedIn:\"0:033-502.el7_4.1\", isSrcPack:false, srcPackName:\"\"}, \"dracut-config-generic\":oval.fixStat{notFixedYet:false, fixedIn:\"0:033-502.el7_4.1\", isSrcPack:false, srcPackName:\"\"}, \"dracut-config-rescue\":oval.fixStat{notFixedYet:false, fixedIn:\"0:033-502.el7_4.1\", isSrcPack:false, srcPackName:\"\"}, \"dracut-network\":oval.fixStat{notFixedYet:false, fixedIn:\"0:033-502.el7_4.1\", isSrcPack:false, srcPackName:\"\"}, \"kernel\":oval.fixStat{notFixedYet:false, fixedIn:\"0:3.10.0-862.el7\", isSrcPack:false, srcPackName:\"\"}, \"kernel-tools\":oval.fixStat{notFixedYet:false, fixedIn:\"0:3.10.0-862.el7\", isSrcPack:false, srcPackName:\"\"}, \"kernel-tools-libs\":oval.fixStat{notFixedYet:false, fixedIn:\"0:3.10.0-862.el7\", isSrcPack:false, srcPackName:\"\"}} 
defPacks.def.DefinitionID = oval:com.redhat.rhsa:def:20181062, cve.CveID = CVE-2017-8824, defPacks.binpkgFixstat = map[string]oval.fixStat{\"dracut\":oval.fixStat{notFixedYet:false, fixedIn:\"0:033-502.el7_4.1\", isSrcPack:false, srcPackName:\"\"}, \"dracut-config-generic\":oval.fixStat{notFixedYet:false, fixedIn:\"0:033-502.el7_4.1\", isSrcPack:false, srcPackName:\"\"}, \"dracut-config-rescue\":oval.fixStat{notFixedYet:false, fixedIn:\"0:033-502.el7_4.1\", isSrcPack:false, srcPackName:\"\"}, \"dracut-network\":oval.fixStat{notFixedYet:false, fixedIn:\"0:033-502.el7_4.1\", isSrcPack:false, srcPackName:\"\"}, \"kernel\":oval.fixStat{notFixedYet:false, fixedIn:\"0:3.10.0-862.el7\", isSrcPack:false, srcPackName:\"\"}, \"kernel-tools\":oval.fixStat{notFixedYet:false, fixedIn:\"0:3.10.0-862.el7\", isSrcPack:false, srcPackName:\"\"}, \"kernel-tools-libs\":oval.fixStat{notFixedYet:false, fixedIn:\"0:3.10.0-862.el7\", isSrcPack:false, srcPackName:\"\"}} 
defPacks.def.DefinitionID = oval:com.redhat.rhsa:def:20181062, cve.CveID = CVE-2017-9725, defPacks.binpkgFixstat = map[string]oval.fixStat{\"dracut\":oval.fixStat{notFixedYet:false, fixedIn:\"0:033-502.el7_4.1\", isSrcPack:false, srcPackName:\"\"}, \"dracut-config-generic\":oval.fixStat{notFixedYet:false, fixedIn:\"0:033-502.el7_4.1\", isSrcPack:false, srcPackName:\"\"}, \"dracut-config-rescue\":oval.fixStat{notFixedYet:false, fixedIn:\"0:033-502.el7_4.1\", isSrcPack:false, srcPackName:\"\"}, \"dracut-network\":oval.fixStat{notFixedYet:false, fixedIn:\"0:033-502.el7_4.1\", isSrcPack:false, srcPackName:\"\"}, \"kernel\":oval.fixStat{notFixedYet:false, fixedIn:\"0:3.10.0-862.el7\", isSrcPack:false, srcPackName:\"\"}, \"kernel-tools\":oval.fixStat{notFixedYet:false, fixedIn:\"0:3.10.0-862.el7\", isSrcPack:false, srcPackName:\"\"}, \"kernel-tools-libs\":oval.fixStat{notFixedYet:false, fixedIn:\"0:3.10.0-862.el7\", isSrcPack:false, srcPackName:\"\"}} 
defPacks.def.DefinitionID = oval:com.redhat.rhsa:def:20181062, cve.CveID = CVE-2018-1000004, defPacks.binpkgFixstat = map[string]oval.fixStat{\"dracut\":oval.fixStat{notFixedYet:false, fixedIn:\"0:033-502.el7_4.1\", isSrcPack:false, srcPackName:\"\"}, \"dracut-config-generic\":oval.fixStat{notFixedYet:false, fixedIn:\"0:033-502.el7_4.1\", isSrcPack:false, srcPackName:\"\"}, \"dracut-config-rescue\":oval.fixStat{notFixedYet:false, fixedIn:\"0:033-502.el7_4.1\", isSrcPack:false, srcPackName:\"\"}, \"dracut-network\":oval.fixStat{notFixedYet:false, fixedIn:\"0:033-502.el7_4.1\", isSrcPack:false, srcPackName:\"\"}, \"kernel\":oval.fixStat{notFixedYet:false, fixedIn:\"0:3.10.0-862.el7\", isSrcPack:false, srcPackName:\"\"}, \"kernel-tools\":oval.fixStat{notFixedYet:false, fixedIn:\"0:3.10.0-862.el7\", isSrcPack:false, srcPackName:\"\"}, \"kernel-tools-libs\":oval.fixStat{notFixedYet:false, fixedIn:\"0:3.10.0-862.el7\", isSrcPack:false, srcPackName:\"\"}} 
defPacks.def.DefinitionID = oval:com.redhat.rhsa:def:20181062, cve.CveID = CVE-2018-1066, defPacks.binpkgFixstat = map[string]oval.fixStat{\"dracut\":oval.fixStat{notFixedYet:false, fixedIn:\"0:033-502.el7_4.1\", isSrcPack:false, srcPackName:\"\"}, \"dracut-config-generic\":oval.fixStat{notFixedYet:false, fixedIn:\"0:033-502.el7_4.1\", isSrcPack:false, srcPackName:\"\"}, \"dracut-config-rescue\":oval.fixStat{notFixedYet:false, fixedIn:\"0:033-502.el7_4.1\", isSrcPack:false, srcPackName:\"\"}, \"dracut-network\":oval.fixStat{notFixedYet:false, fixedIn:\"0:033-502.el7_4.1\", isSrcPack:false, srcPackName:\"\"}, \"kernel\":oval.fixStat{notFixedYet:false, fixedIn:\"0:3.10.0-862.el7\", isSrcPack:false, srcPackName:\"\"}, \"kernel-tools\":oval.fixStat{notFixedYet:false, fixedIn:\"0:3.10.0-862.el7\", isSrcPack:false, srcPackName:\"\"}, \"kernel-tools-libs\":oval.fixStat{notFixedYet:false, fixedIn:\"0:3.10.0-862.el7\", isSrcPack:false, srcPackName:\"\"}} 
defPacks.def.DefinitionID = oval:com.redhat.rhsa:def:20181062, cve.CveID = CVE-2018-5750, defPacks.binpkgFixstat = map[string]oval.fixStat{\"dracut\":oval.fixStat{notFixedYet:false, fixedIn:\"0:033-502.el7_4.1\", isSrcPack:false, srcPackName:\"\"}, \"dracut-config-generic\":oval.fixStat{notFixedYet:false, fixedIn:\"0:033-502.el7_4.1\", isSrcPack:false, srcPackName:\"\"}, \"dracut-config-rescue\":oval.fixStat{notFixedYet:false, fixedIn:\"0:033-502.el7_4.1\", isSrcPack:false, srcPackName:\"\"}, \"dracut-network\":oval.fixStat{notFixedYet:false, fixedIn:\"0:033-502.el7_4.1\", isSrcPack:false, srcPackName:\"\"}, \"kernel\":oval.fixStat{notFixedYet:false, fixedIn:\"0:3.10.0-862.el7\", isSrcPack:false, srcPackName:\"\"}, \"kernel-tools\":oval.fixStat{notFixedYet:false, fixedIn:\"0:3.10.0-862.el7\", isSrcPack:false, srcPackName:\"\"}, \"kernel-tools-libs\":oval.fixStat{notFixedYet:false, fixedIn:\"0:3.10.0-862.el7\", isSrcPack:false, srcPackName:\"\"}} 
defPacks.def.DefinitionID = oval:com.redhat.rhsa:def:20181062, cve.CveID = CVE-2018-6927, defPacks.binpkgFixstat = map[string]oval.fixStat{\"dracut\":oval.fixStat{notFixedYet:false, fixedIn:\"0:033-502.el7_4.1\", isSrcPack:false, srcPackName:\"\"}, \"dracut-config-generic\":oval.fixStat{notFixedYet:false, fixedIn:\"0:033-502.el7_4.1\", isSrcPack:false, srcPackName:\"\"}, \"dracut-config-rescue\":oval.fixStat{notFixedYet:false, fixedIn:\"0:033-502.el7_4.1\", isSrcPack:false, srcPackName:\"\"}, \"dracut-network\":oval.fixStat{notFixedYet:false, fixedIn:\"0:033-502.el7_4.1\", isSrcPack:false, srcPackName:\"\"}, \"kernel\":oval.fixStat{notFixedYet:false, fixedIn:\"0:3.10.0-862.el7\", isSrcPack:false, srcPackName:\"\"}, \"kernel-tools\":oval.fixStat{notFixedYet:false, fixedIn:\"0:3.10.0-862.el7\", isSrcPack:false, srcPackName:\"\"}, \"kernel-tools-libs\":oval.fixStat{notFixedYet:false, fixedIn:\"0:3.10.0-862.el7\", isSrcPack:false, srcPackName:\"\"}} 

But, in the newmodel of goval-dictionary, the order of CVEs is not fixed, so the following behavior occurred.
After the timing of CVE-2017-5715, the difference will appear in defPacks.binpkgFixstat.

defPacks.def.DefinitionID = oval:com.redhat.rhsa:def:20181062, cve.CveID = CVE-2017-1000407, defPacks.binpkgFixstat = map[string]oval.fixStat{\"kernel\":oval.fixStat{notFixedYet:false, fixedIn:\"0:3.10.0-862.el7\", isSrcPack:false, srcPackName:\"\"}, \"kernel-tools\":oval.fixStat{notFixedYet:false, fixedIn:\"0:3.10.0-862.el7\", isSrcPack:false, srcPackName:\"\"}, \"kernel-tools-libs\":oval.fixStat{notFixedYet:false, fixedIn:\"0:3.10.0-862.el7\", isSrcPack:false, srcPackName:\"\"}} 
defPacks.def.DefinitionID = oval:com.redhat.rhsa:def:20181062, cve.CveID = CVE-2017-5715, defPacks.binpkgFixstat = map[string]oval.fixStat{\"dracut\":oval.fixStat{notFixedYet:false, fixedIn:\"0:033-502.el7_4.1\", isSrcPack:false, srcPackName:\"\"}, \"dracut-config-generic\":oval.fixStat{notFixedYet:false, fixedIn:\"0:033-502.el7_4.1\", isSrcPack:false, srcPackName:\"\"}, \"dracut-config-rescue\":oval.fixStat{notFixedYet:false, fixedIn:\"0:033-502.el7_4.1\", isSrcPack:false, srcPackName:\"\"}, \"dracut-network\":oval.fixStat{notFixedYet:false, fixedIn:\"0:033-502.el7_4.1\", isSrcPack:false, srcPackName:\"\"}, \"kernel\":oval.fixStat{notFixedYet:false, fixedIn:\"0:3.10.0-862.el7\", isSrcPack:false, srcPackName:\"\"}, \"kernel-tools\":oval.fixStat{notFixedYet:false, fixedIn:\"0:3.10.0-862.el7\", isSrcPack:false, srcPackName:\"\"}, \"kernel-tools-libs\":oval.fixStat{notFixedYet:false, fixedIn:\"0:3.10.0-862.el7\", isSrcPack:false, srcPackName:\"\"}} 
defPacks.def.DefinitionID = oval:com.redhat.rhsa:def:20181062, cve.CveID = CVE-2017-8824, defPacks.binpkgFixstat = map[string]oval.fixStat{\"dracut\":oval.fixStat{notFixedYet:false, fixedIn:\"0:033-502.el7_4.1\", isSrcPack:false, srcPackName:\"\"}, \"dracut-config-generic\":oval.fixStat{notFixedYet:false, fixedIn:\"0:033-502.el7_4.1\", isSrcPack:false, srcPackName:\"\"}, \"dracut-config-rescue\":oval.fixStat{notFixedYet:false, fixedIn:\"0:033-502.el7_4.1\", isSrcPack:false, srcPackName:\"\"}, \"dracut-network\":oval.fixStat{notFixedYet:false, fixedIn:\"0:033-502.el7_4.1\", isSrcPack:false, srcPackName:\"\"}, \"kernel\":oval.fixStat{notFixedYet:false, fixedIn:\"0:3.10.0-862.el7\", isSrcPack:false, srcPackName:\"\"}, \"kernel-tools\":oval.fixStat{notFixedYet:false, fixedIn:\"0:3.10.0-862.el7\", isSrcPack:false, srcPackName:\"\"}, \"kernel-tools-libs\":oval.fixStat{notFixedYet:false, fixedIn:\"0:3.10.0-862.el7\", isSrcPack:false, srcPackName:\"\"}} 
defPacks.def.DefinitionID = oval:com.redhat.rhsa:def:20181062, cve.CveID = CVE-2017-14140, defPacks.binpkgFixstat = map[string]oval.fixStat{\"dracut\":oval.fixStat{notFixedYet:false, fixedIn:\"0:033-502.el7_4.1\", isSrcPack:false, srcPackName:\"\"}, \"dracut-config-generic\":oval.fixStat{notFixedYet:false, fixedIn:\"0:033-502.el7_4.1\", isSrcPack:false, srcPackName:\"\"}, \"dracut-config-rescue\":oval.fixStat{notFixedYet:false, fixedIn:\"0:033-502.el7_4.1\", isSrcPack:false, srcPackName:\"\"}, \"dracut-network\":oval.fixStat{notFixedYet:false, fixedIn:\"0:033-502.el7_4.1\", isSrcPack:false, srcPackName:\"\"}, \"kernel\":oval.fixStat{notFixedYet:false, fixedIn:\"0:3.10.0-862.el7\", isSrcPack:false, srcPackName:\"\"}, \"kernel-tools\":oval.fixStat{notFixedYet:false, fixedIn:\"0:3.10.0-862.el7\", isSrcPack:false, srcPackName:\"\"}, \"kernel-tools-libs\":oval.fixStat{notFixedYet:false, fixedIn:\"0:3.10.0-862.el7\", isSrcPack:false, srcPackName:\"\"}} 
defPacks.def.DefinitionID = oval:com.redhat.rhsa:def:20181062, cve.CveID = CVE-2017-9725, defPacks.binpkgFixstat = map[string]oval.fixStat{\"dracut\":oval.fixStat{notFixedYet:false, fixedIn:\"0:033-502.el7_4.1\", isSrcPack:false, srcPackName:\"\"}, \"dracut-config-generic\":oval.fixStat{notFixedYet:false, fixedIn:\"0:033-502.el7_4.1\", isSrcPack:false, srcPackName:\"\"}, \"dracut-config-rescue\":oval.fixStat{notFixedYet:false, fixedIn:\"0:033-502.el7_4.1\", isSrcPack:false, srcPackName:\"\"}, \"dracut-network\":oval.fixStat{notFixedYet:false, fixedIn:\"0:033-502.el7_4.1\", isSrcPack:false, srcPackName:\"\"}, \"kernel\":oval.fixStat{notFixedYet:false, fixedIn:\"0:3.10.0-862.el7\", isSrcPack:false, srcPackName:\"\"}, \"kernel-tools\":oval.fixStat{notFixedYet:false, fixedIn:\"0:3.10.0-862.el7\", isSrcPack:false, srcPackName:\"\"}, \"kernel-tools-libs\":oval.fixStat{notFixedYet:false, fixedIn:\"0:3.10.0-862.el7\", isSrcPack:false, srcPackName:\"\"}} 
defPacks.def.DefinitionID = oval:com.redhat.rhsa:def:20181062, cve.CveID = CVE-2017-17449, defPacks.binpkgFixstat = map[string]oval.fixStat{\"dracut\":oval.fixStat{notFixedYet:false, fixedIn:\"0:033-502.el7_4.1\", isSrcPack:false, srcPackName:\"\"}, \"dracut-config-generic\":oval.fixStat{notFixedYet:false, fixedIn:\"0:033-502.el7_4.1\", isSrcPack:false, srcPackName:\"\"}, \"dracut-config-rescue\":oval.fixStat{notFixedYet:false, fixedIn:\"0:033-502.el7_4.1\", isSrcPack:false, srcPackName:\"\"}, \"dracut-network\":oval.fixStat{notFixedYet:false, fixedIn:\"0:033-502.el7_4.1\", isSrcPack:false, srcPackName:\"\"}, \"kernel\":oval.fixStat{notFixedYet:false, fixedIn:\"0:3.10.0-862.el7\", isSrcPack:false, srcPackName:\"\"}, \"kernel-tools\":oval.fixStat{notFixedYet:false, fixedIn:\"0:3.10.0-862.el7\", isSrcPack:false, srcPackName:\"\"}, \"kernel-tools-libs\":oval.fixStat{notFixedYet:false, fixedIn:\"0:3.10.0-862.el7\", isSrcPack:false, srcPackName:\"\"}} 
defPacks.def.DefinitionID = oval:com.redhat.rhsa:def:20181062, cve.CveID = CVE-2017-12154, defPacks.binpkgFixstat = map[string]oval.fixStat{\"dracut\":oval.fixStat{notFixedYet:false, fixedIn:\"0:033-502.el7_4.1\", isSrcPack:false, srcPackName:\"\"}, \"dracut-config-generic\":oval.fixStat{notFixedYet:false, fixedIn:\"0:033-502.el7_4.1\", isSrcPack:false, srcPackName:\"\"}, \"dracut-config-rescue\":oval.fixStat{notFixedYet:false, fixedIn:\"0:033-502.el7_4.1\", isSrcPack:false, srcPackName:\"\"}, \"dracut-network\":oval.fixStat{notFixedYet:false, fixedIn:\"0:033-502.el7_4.1\", isSrcPack:false, srcPackName:\"\"}, \"kernel\":oval.fixStat{notFixedYet:false, fixedIn:\"0:3.10.0-862.el7\", isSrcPack:false, srcPackName:\"\"}, \"kernel-tools\":oval.fixStat{notFixedYet:false, fixedIn:\"0:3.10.0-862.el7\", isSrcPack:false, srcPackName:\"\"}, \"kernel-tools-libs\":oval.fixStat{notFixedYet:false, fixedIn:\"0:3.10.0-862.el7\", isSrcPack:false, srcPackName:\"\"}} 
defPacks.def.DefinitionID = oval:com.redhat.rhsa:def:20181062, cve.CveID = CVE-2017-15116, defPacks.binpkgFixstat = map[string]oval.fixStat{\"dracut\":oval.fixStat{notFixedYet:false, fixedIn:\"0:033-502.el7_4.1\", isSrcPack:false, srcPackName:\"\"}, \"dracut-config-generic\":oval.fixStat{notFixedYet:false, fixedIn:\"0:033-502.el7_4.1\", isSrcPack:false, srcPackName:\"\"}, \"dracut-config-rescue\":oval.fixStat{notFixedYet:false, fixedIn:\"0:033-502.el7_4.1\", isSrcPack:false, srcPackName:\"\"}, \"dracut-network\":oval.fixStat{notFixedYet:false, fixedIn:\"0:033-502.el7_4.1\", isSrcPack:false, srcPackName:\"\"}, \"kernel\":oval.fixStat{notFixedYet:false, fixedIn:\"0:3.10.0-862.el7\", isSrcPack:false, srcPackName:\"\"}, \"kernel-tools\":oval.fixStat{notFixedYet:false, fixedIn:\"0:3.10.0-862.el7\", isSrcPack:false, srcPackName:\"\"}, \"kernel-tools-libs\":oval.fixStat{notFixedYet:false, fixedIn:\"0:3.10.0-862.el7\", isSrcPack:false, srcPackName:\"\"}} 
defPacks.def.DefinitionID = oval:com.redhat.rhsa:def:20181062, cve.CveID = CVE-2017-15274, defPacks.binpkgFixstat = map[string]oval.fixStat{\"dracut\":oval.fixStat{notFixedYet:false, fixedIn:\"0:033-502.el7_4.1\", isSrcPack:false, srcPackName:\"\"}, \"dracut-config-generic\":oval.fixStat{notFixedYet:false, fixedIn:\"0:033-502.el7_4.1\", isSrcPack:false, srcPackName:\"\"}, \"dracut-config-rescue\":oval.fixStat{notFixedYet:false, fixedIn:\"0:033-502.el7_4.1\", isSrcPack:false, srcPackName:\"\"}, \"dracut-network\":oval.fixStat{notFixedYet:false, fixedIn:\"0:033-502.el7_4.1\", isSrcPack:false, srcPackName:\"\"}, \"kernel\":oval.fixStat{notFixedYet:false, fixedIn:\"0:3.10.0-862.el7\", isSrcPack:false, srcPackName:\"\"}, \"kernel-tools\":oval.fixStat{notFixedYet:false, fixedIn:\"0:3.10.0-862.el7\", isSrcPack:false, srcPackName:\"\"}, \"kernel-tools-libs\":oval.fixStat{notFixedYet:false, fixedIn:\"0:3.10.0-862.el7\", isSrcPack:false, srcPackName:\"\"}} 
defPacks.def.DefinitionID = oval:com.redhat.rhsa:def:20181062, cve.CveID = CVE-2017-5754, defPacks.binpkgFixstat = map[string]oval.fixStat{\"dracut\":oval.fixStat{notFixedYet:false, fixedIn:\"0:033-502.el7_4.1\", isSrcPack:false, srcPackName:\"\"}, \"dracut-config-generic\":oval.fixStat{notFixedYet:false, fixedIn:\"0:033-502.el7_4.1\", isSrcPack:false, srcPackName:\"\"}, \"dracut-config-rescue\":oval.fixStat{notFixedYet:false, fixedIn:\"0:033-502.el7_4.1\", isSrcPack:false, srcPackName:\"\"}, \"dracut-network\":oval.fixStat{notFixedYet:false, fixedIn:\"0:033-502.el7_4.1\", isSrcPack:false, srcPackName:\"\"}, \"kernel\":oval.fixStat{notFixedYet:false, fixedIn:\"0:3.10.0-862.el7\", isSrcPack:false, srcPackName:\"\"}, \"kernel-tools\":oval.fixStat{notFixedYet:false, fixedIn:\"0:3.10.0-862.el7\", isSrcPack:false, srcPackName:\"\"}, \"kernel-tools-libs\":oval.fixStat{notFixedYet:false, fixedIn:\"0:3.10.0-862.el7\", isSrcPack:false, srcPackName:\"\"}} 
defPacks.def.DefinitionID = oval:com.redhat.rhsa:def:20181062, cve.CveID = CVE-2017-15126, defPacks.binpkgFixstat = map[string]oval.fixStat{\"dracut\":oval.fixStat{notFixedYet:false, fixedIn:\"0:033-502.el7_4.1\", isSrcPack:false, srcPackName:\"\"}, \"dracut-config-generic\":oval.fixStat{notFixedYet:false, fixedIn:\"0:033-502.el7_4.1\", isSrcPack:false, srcPackName:\"\"}, \"dracut-config-rescue\":oval.fixStat{notFixedYet:false, fixedIn:\"0:033-502.el7_4.1\", isSrcPack:false, srcPackName:\"\"}, \"dracut-network\":oval.fixStat{notFixedYet:false, fixedIn:\"0:033-502.el7_4.1\", isSrcPack:false, srcPackName:\"\"}, \"kernel\":oval.fixStat{notFixedYet:false, fixedIn:\"0:3.10.0-862.el7\", isSrcPack:false, srcPackName:\"\"}, \"kernel-tools\":oval.fixStat{notFixedYet:false, fixedIn:\"0:3.10.0-862.el7\", isSrcPack:false, srcPackName:\"\"}, \"kernel-tools-libs\":oval.fixStat{notFixedYet:false, fixedIn:\"0:3.10.0-862.el7\", isSrcPack:false, srcPackName:\"\"}} 
defPacks.def.DefinitionID = oval:com.redhat.rhsa:def:20181062, cve.CveID = CVE-2017-18017, defPacks.binpkgFixstat = map[string]oval.fixStat{\"dracut\":oval.fixStat{notFixedYet:false, fixedIn:\"0:033-502.el7_4.1\", isSrcPack:false, srcPackName:\"\"}, \"dracut-config-generic\":oval.fixStat{notFixedYet:false, fixedIn:\"0:033-502.el7_4.1\", isSrcPack:false, srcPackName:\"\"}, \"dracut-config-rescue\":oval.fixStat{notFixedYet:false, fixedIn:\"0:033-502.el7_4.1\", isSrcPack:false, srcPackName:\"\"}, \"dracut-network\":oval.fixStat{notFixedYet:false, fixedIn:\"0:033-502.el7_4.1\", isSrcPack:false, srcPackName:\"\"}, \"kernel\":oval.fixStat{notFixedYet:false, fixedIn:\"0:3.10.0-862.el7\", isSrcPack:false, srcPackName:\"\"}, \"kernel-tools\":oval.fixStat{notFixedYet:false, fixedIn:\"0:3.10.0-862.el7\", isSrcPack:false, srcPackName:\"\"}, \"kernel-tools-libs\":oval.fixStat{notFixedYet:false, fixedIn:\"0:3.10.0-862.el7\", isSrcPack:false, srcPackName:\"\"}} 
defPacks.def.DefinitionID = oval:com.redhat.rhsa:def:20181062, cve.CveID = CVE-2018-1000004, defPacks.binpkgFixstat = map[string]oval.fixStat{\"dracut\":oval.fixStat{notFixedYet:false, fixedIn:\"0:033-502.el7_4.1\", isSrcPack:false, srcPackName:\"\"}, \"dracut-config-generic\":oval.fixStat{notFixedYet:false, fixedIn:\"0:033-502.el7_4.1\", isSrcPack:false, srcPackName:\"\"}, \"dracut-config-rescue\":oval.fixStat{notFixedYet:false, fixedIn:\"0:033-502.el7_4.1\", isSrcPack:false, srcPackName:\"\"}, \"dracut-network\":oval.fixStat{notFixedYet:false, fixedIn:\"0:033-502.el7_4.1\", isSrcPack:false, srcPackName:\"\"}, \"kernel\":oval.fixStat{notFixedYet:false, fixedIn:\"0:3.10.0-862.el7\", isSrcPack:false, srcPackName:\"\"}, \"kernel-tools\":oval.fixStat{notFixedYet:false, fixedIn:\"0:3.10.0-862.el7\", isSrcPack:false, srcPackName:\"\"}, \"kernel-tools-libs\":oval.fixStat{notFixedYet:false, fixedIn:\"0:3.10.0-862.el7\", isSrcPack:false, srcPackName:\"\"}} 
defPacks.def.DefinitionID = oval:com.redhat.rhsa:def:20181062, cve.CveID = CVE-2016-3672, defPacks.binpkgFixstat = map[string]oval.fixStat{\"dracut\":oval.fixStat{notFixedYet:false, fixedIn:\"0:033-502.el7_4.1\", isSrcPack:false, srcPackName:\"\"}, \"dracut-config-generic\":oval.fixStat{notFixedYet:false, fixedIn:\"0:033-502.el7_4.1\", isSrcPack:false, srcPackName:\"\"}, \"dracut-config-rescue\":oval.fixStat{notFixedYet:false, fixedIn:\"0:033-502.el7_4.1\", isSrcPack:false, srcPackName:\"\"}, \"dracut-network\":oval.fixStat{notFixedYet:false, fixedIn:\"0:033-502.el7_4.1\", isSrcPack:false, srcPackName:\"\"}, \"kernel\":oval.fixStat{notFixedYet:false, fixedIn:\"0:3.10.0-862.el7\", isSrcPack:false, srcPackName:\"\"}, \"kernel-tools\":oval.fixStat{notFixedYet:false, fixedIn:\"0:3.10.0-862.el7\", isSrcPack:false, srcPackName:\"\"}, \"kernel-tools-libs\":oval.fixStat{notFixedYet:false, fixedIn:\"0:3.10.0-862.el7\", isSrcPack:false, srcPackName:\"\"}} 
defPacks.def.DefinitionID = oval:com.redhat.rhsa:def:20181062, cve.CveID = CVE-2017-1000252, defPacks.binpkgFixstat = map[string]oval.fixStat{\"dracut\":oval.fixStat{notFixedYet:false, fixedIn:\"0:033-502.el7_4.1\", isSrcPack:false, srcPackName:\"\"}, \"dracut-config-generic\":oval.fixStat{notFixedYet:false, fixedIn:\"0:033-502.el7_4.1\", isSrcPack:false, srcPackName:\"\"}, \"dracut-config-rescue\":oval.fixStat{notFixedYet:false, fixedIn:\"0:033-502.el7_4.1\", isSrcPack:false, srcPackName:\"\"}, \"dracut-network\":oval.fixStat{notFixedYet:false, fixedIn:\"0:033-502.el7_4.1\", isSrcPack:false, srcPackName:\"\"}, \"kernel\":oval.fixStat{notFixedYet:false, fixedIn:\"0:3.10.0-862.el7\", isSrcPack:false, srcPackName:\"\"}, \"kernel-tools\":oval.fixStat{notFixedYet:false, fixedIn:\"0:3.10.0-862.el7\", isSrcPack:false, srcPackName:\"\"}, \"kernel-tools-libs\":oval.fixStat{notFixedYet:false, fixedIn:\"0:3.10.0-862.el7\", isSrcPack:false, srcPackName:\"\"}} 
defPacks.def.DefinitionID = oval:com.redhat.rhsa:def:20181062, cve.CveID = CVE-2017-1000410, defPacks.binpkgFixstat = map[string]oval.fixStat{\"dracut\":oval.fixStat{notFixedYet:false, fixedIn:\"0:033-502.el7_4.1\", isSrcPack:false, srcPackName:\"\"}, \"dracut-config-generic\":oval.fixStat{notFixedYet:false, fixedIn:\"0:033-502.el7_4.1\", isSrcPack:false, srcPackName:\"\"}, \"dracut-config-rescue\":oval.fixStat{notFixedYet:false, fixedIn:\"0:033-502.el7_4.1\", isSrcPack:false, srcPackName:\"\"}, \"dracut-network\":oval.fixStat{notFixedYet:false, fixedIn:\"0:033-502.el7_4.1\", isSrcPack:false, srcPackName:\"\"}, \"kernel\":oval.fixStat{notFixedYet:false, fixedIn:\"0:3.10.0-862.el7\", isSrcPack:false, srcPackName:\"\"}, \"kernel-tools\":oval.fixStat{notFixedYet:false, fixedIn:\"0:3.10.0-862.el7\", isSrcPack:false, srcPackName:\"\"}, \"kernel-tools-libs\":oval.fixStat{notFixedYet:false, fixedIn:\"0:3.10.0-862.el7\", isSrcPack:false, srcPackName:\"\"}} 
defPacks.def.DefinitionID = oval:com.redhat.rhsa:def:20181062, cve.CveID = CVE-2017-15121, defPacks.binpkgFixstat = map[string]oval.fixStat{\"dracut\":oval.fixStat{notFixedYet:false, fixedIn:\"0:033-502.el7_4.1\", isSrcPack:false, srcPackName:\"\"}, \"dracut-config-generic\":oval.fixStat{notFixedYet:false, fixedIn:\"0:033-502.el7_4.1\", isSrcPack:false, srcPackName:\"\"}, \"dracut-config-rescue\":oval.fixStat{notFixedYet:false, fixedIn:\"0:033-502.el7_4.1\", isSrcPack:false, srcPackName:\"\"}, \"dracut-network\":oval.fixStat{notFixedYet:false, fixedIn:\"0:033-502.el7_4.1\", isSrcPack:false, srcPackName:\"\"}, \"kernel\":oval.fixStat{notFixedYet:false, fixedIn:\"0:3.10.0-862.el7\", isSrcPack:false, srcPackName:\"\"}, \"kernel-tools\":oval.fixStat{notFixedYet:false, fixedIn:\"0:3.10.0-862.el7\", isSrcPack:false, srcPackName:\"\"}, \"kernel-tools-libs\":oval.fixStat{notFixedYet:false, fixedIn:\"0:3.10.0-862.el7\", isSrcPack:false, srcPackName:\"\"}} 
defPacks.def.DefinitionID = oval:com.redhat.rhsa:def:20181062, cve.CveID = CVE-2017-18203, defPacks.binpkgFixstat = map[string]oval.fixStat{\"dracut\":oval.fixStat{notFixedYet:false, fixedIn:\"0:033-502.el7_4.1\", isSrcPack:false, srcPackName:\"\"}, \"dracut-config-generic\":oval.fixStat{notFixedYet:false, fixedIn:\"0:033-502.el7_4.1\", isSrcPack:false, srcPackName:\"\"}, \"dracut-config-rescue\":oval.fixStat{notFixedYet:false, fixedIn:\"0:033-502.el7_4.1\", isSrcPack:false, srcPackName:\"\"}, \"dracut-network\":oval.fixStat{notFixedYet:false, fixedIn:\"0:033-502.el7_4.1\", isSrcPack:false, srcPackName:\"\"}, \"kernel\":oval.fixStat{notFixedYet:false, fixedIn:\"0:3.10.0-862.el7\", isSrcPack:false, srcPackName:\"\"}, \"kernel-tools\":oval.fixStat{notFixedYet:false, fixedIn:\"0:3.10.0-862.el7\", isSrcPack:false, srcPackName:\"\"}, \"kernel-tools-libs\":oval.fixStat{notFixedYet:false, fixedIn:\"0:3.10.0-862.el7\", isSrcPack:false, srcPackName:\"\"}} 
defPacks.def.DefinitionID = oval:com.redhat.rhsa:def:20181062, cve.CveID = CVE-2017-18270, defPacks.binpkgFixstat = map[string]oval.fixStat{\"dracut\":oval.fixStat{notFixedYet:false, fixedIn:\"0:033-502.el7_4.1\", isSrcPack:false, srcPackName:\"\"}, \"dracut-config-generic\":oval.fixStat{notFixedYet:false, fixedIn:\"0:033-502.el7_4.1\", isSrcPack:false, srcPackName:\"\"}, \"dracut-config-rescue\":oval.fixStat{notFixedYet:false, fixedIn:\"0:033-502.el7_4.1\", isSrcPack:false, srcPackName:\"\"}, \"dracut-network\":oval.fixStat{notFixedYet:false, fixedIn:\"0:033-502.el7_4.1\", isSrcPack:false, srcPackName:\"\"}, \"kernel\":oval.fixStat{notFixedYet:false, fixedIn:\"0:3.10.0-862.el7\", isSrcPack:false, srcPackName:\"\"}, \"kernel-tools\":oval.fixStat{notFixedYet:false, fixedIn:\"0:3.10.0-862.el7\", isSrcPack:false, srcPackName:\"\"}, \"kernel-tools-libs\":oval.fixStat{notFixedYet:false, fixedIn:\"0:3.10.0-862.el7\", isSrcPack:false, srcPackName:\"\"}} 
defPacks.def.DefinitionID = oval:com.redhat.rhsa:def:20181062, cve.CveID = CVE-2018-1066, defPacks.binpkgFixstat = map[string]oval.fixStat{\"dracut\":oval.fixStat{notFixedYet:false, fixedIn:\"0:033-502.el7_4.1\", isSrcPack:false, srcPackName:\"\"}, \"dracut-config-generic\":oval.fixStat{notFixedYet:false, fixedIn:\"0:033-502.el7_4.1\", isSrcPack:false, srcPackName:\"\"}, \"dracut-config-rescue\":oval.fixStat{notFixedYet:false, fixedIn:\"0:033-502.el7_4.1\", isSrcPack:false, srcPackName:\"\"}, \"dracut-network\":oval.fixStat{notFixedYet:false, fixedIn:\"0:033-502.el7_4.1\", isSrcPack:false, srcPackName:\"\"}, \"kernel\":oval.fixStat{notFixedYet:false, fixedIn:\"0:3.10.0-862.el7\", isSrcPack:false, srcPackName:\"\"}, \"kernel-tools\":oval.fixStat{notFixedYet:false, fixedIn:\"0:3.10.0-862.el7\", isSrcPack:false, srcPackName:\"\"}, \"kernel-tools-libs\":oval.fixStat{notFixedYet:false, fixedIn:\"0:3.10.0-862.el7\", isSrcPack:false, srcPackName:\"\"}} 
defPacks.def.DefinitionID = oval:com.redhat.rhsa:def:20181062, cve.CveID = CVE-2018-5750, defPacks.binpkgFixstat = map[string]oval.fixStat{\"dracut\":oval.fixStat{notFixedYet:false, fixedIn:\"0:033-502.el7_4.1\", isSrcPack:false, srcPackName:\"\"}, \"dracut-config-generic\":oval.fixStat{notFixedYet:false, fixedIn:\"0:033-502.el7_4.1\", isSrcPack:false, srcPackName:\"\"}, \"dracut-config-rescue\":oval.fixStat{notFixedYet:false, fixedIn:\"0:033-502.el7_4.1\", isSrcPack:false, srcPackName:\"\"}, \"dracut-network\":oval.fixStat{notFixedYet:false, fixedIn:\"0:033-502.el7_4.1\", isSrcPack:false, srcPackName:\"\"}, \"kernel\":oval.fixStat{notFixedYet:false, fixedIn:\"0:3.10.0-862.el7\", isSrcPack:false, srcPackName:\"\"}, \"kernel-tools\":oval.fixStat{notFixedYet:false, fixedIn:\"0:3.10.0-862.el7\", isSrcPack:false, srcPackName:\"\"}, \"kernel-tools-libs\":oval.fixStat{notFixedYet:false, fixedIn:\"0:3.10.0-862.el7\", isSrcPack:false, srcPackName:\"\"}} 
defPacks.def.DefinitionID = oval:com.redhat.rhsa:def:20181062, cve.CveID = CVE-2016-7913, defPacks.binpkgFixstat = map[string]oval.fixStat{\"dracut\":oval.fixStat{notFixedYet:false, fixedIn:\"0:033-502.el7_4.1\", isSrcPack:false, srcPackName:\"\"}, \"dracut-config-generic\":oval.fixStat{notFixedYet:false, fixedIn:\"0:033-502.el7_4.1\", isSrcPack:false, srcPackName:\"\"}, \"dracut-config-rescue\":oval.fixStat{notFixedYet:false, fixedIn:\"0:033-502.el7_4.1\", isSrcPack:false, srcPackName:\"\"}, \"dracut-network\":oval.fixStat{notFixedYet:false, fixedIn:\"0:033-502.el7_4.1\", isSrcPack:false, srcPackName:\"\"}, \"kernel\":oval.fixStat{notFixedYet:false, fixedIn:\"0:3.10.0-862.el7\", isSrcPack:false, srcPackName:\"\"}, \"kernel-tools\":oval.fixStat{notFixedYet:false, fixedIn:\"0:3.10.0-862.el7\", isSrcPack:false, srcPackName:\"\"}, \"kernel-tools-libs\":oval.fixStat{notFixedYet:false, fixedIn:\"0:3.10.0-862.el7\", isSrcPack:false, srcPackName:\"\"}} 
defPacks.def.DefinitionID = oval:com.redhat.rhsa:def:20181062, cve.CveID = CVE-2017-13166, defPacks.binpkgFixstat = map[string]oval.fixStat{\"dracut\":oval.fixStat{notFixedYet:false, fixedIn:\"0:033-502.el7_4.1\", isSrcPack:false, srcPackName:\"\"}, \"dracut-config-generic\":oval.fixStat{notFixedYet:false, fixedIn:\"0:033-502.el7_4.1\", isSrcPack:false, srcPackName:\"\"}, \"dracut-config-rescue\":oval.fixStat{notFixedYet:false, fixedIn:\"0:033-502.el7_4.1\", isSrcPack:false, srcPackName:\"\"}, \"dracut-network\":oval.fixStat{notFixedYet:false, fixedIn:\"0:033-502.el7_4.1\", isSrcPack:false, srcPackName:\"\"}, \"kernel\":oval.fixStat{notFixedYet:false, fixedIn:\"0:3.10.0-862.el7\", isSrcPack:false, srcPackName:\"\"}, \"kernel-tools\":oval.fixStat{notFixedYet:false, fixedIn:\"0:3.10.0-862.el7\", isSrcPack:false, srcPackName:\"\"}, \"kernel-tools-libs\":oval.fixStat{notFixedYet:false, fixedIn:\"0:3.10.0-862.el7\", isSrcPack:false, srcPackName:\"\"}} 
defPacks.def.DefinitionID = oval:com.redhat.rhsa:def:20181062, cve.CveID = CVE-2017-15129, defPacks.binpkgFixstat = map[string]oval.fixStat{\"dracut\":oval.fixStat{notFixedYet:false, fixedIn:\"0:033-502.el7_4.1\", isSrcPack:false, srcPackName:\"\"}, \"dracut-config-generic\":oval.fixStat{notFixedYet:false, fixedIn:\"0:033-502.el7_4.1\", isSrcPack:false, srcPackName:\"\"}, \"dracut-config-rescue\":oval.fixStat{notFixedYet:false, fixedIn:\"0:033-502.el7_4.1\", isSrcPack:false, srcPackName:\"\"}, \"dracut-network\":oval.fixStat{notFixedYet:false, fixedIn:\"0:033-502.el7_4.1\", isSrcPack:false, srcPackName:\"\"}, \"kernel\":oval.fixStat{notFixedYet:false, fixedIn:\"0:3.10.0-862.el7\", isSrcPack:false, srcPackName:\"\"}, \"kernel-tools\":oval.fixStat{notFixedYet:false, fixedIn:\"0:3.10.0-862.el7\", isSrcPack:false, srcPackName:\"\"}, \"kernel-tools-libs\":oval.fixStat{notFixedYet:false, fixedIn:\"0:3.10.0-862.el7\", isSrcPack:false, srcPackName:\"\"}} 
defPacks.def.DefinitionID = oval:com.redhat.rhsa:def:20181062, cve.CveID = CVE-2017-17448, defPacks.binpkgFixstat = map[string]oval.fixStat{\"dracut\":oval.fixStat{notFixedYet:false, fixedIn:\"0:033-502.el7_4.1\", isSrcPack:false, srcPackName:\"\"}, \"dracut-config-generic\":oval.fixStat{notFixedYet:false, fixedIn:\"0:033-502.el7_4.1\", isSrcPack:false, srcPackName:\"\"}, \"dracut-config-rescue\":oval.fixStat{notFixedYet:false, fixedIn:\"0:033-502.el7_4.1\", isSrcPack:false, srcPackName:\"\"}, \"dracut-network\":oval.fixStat{notFixedYet:false, fixedIn:\"0:033-502.el7_4.1\", isSrcPack:false, srcPackName:\"\"}, \"kernel\":oval.fixStat{notFixedYet:false, fixedIn:\"0:3.10.0-862.el7\", isSrcPack:false, srcPackName:\"\"}, \"kernel-tools\":oval.fixStat{notFixedYet:false, fixedIn:\"0:3.10.0-862.el7\", isSrcPack:false, srcPackName:\"\"}, \"kernel-tools-libs\":oval.fixStat{notFixedYet:false, fixedIn:\"0:3.10.0-862.el7\", isSrcPack:false, srcPackName:\"\"}} 
defPacks.def.DefinitionID = oval:com.redhat.rhsa:def:20181062, cve.CveID = CVE-2017-12190, defPacks.binpkgFixstat = map[string]oval.fixStat{\"dracut\":oval.fixStat{notFixedYet:false, fixedIn:\"0:033-502.el7_4.1\", isSrcPack:false, srcPackName:\"\"}, \"dracut-config-generic\":oval.fixStat{notFixedYet:false, fixedIn:\"0:033-502.el7_4.1\", isSrcPack:false, srcPackName:\"\"}, \"dracut-config-rescue\":oval.fixStat{notFixedYet:false, fixedIn:\"0:033-502.el7_4.1\", isSrcPack:false, srcPackName:\"\"}, \"dracut-network\":oval.fixStat{notFixedYet:false, fixedIn:\"0:033-502.el7_4.1\", isSrcPack:false, srcPackName:\"\"}, \"kernel\":oval.fixStat{notFixedYet:false, fixedIn:\"0:3.10.0-862.el7\", isSrcPack:false, srcPackName:\"\"}, \"kernel-tools\":oval.fixStat{notFixedYet:false, fixedIn:\"0:3.10.0-862.el7\", isSrcPack:false, srcPackName:\"\"}, \"kernel-tools-libs\":oval.fixStat{notFixedYet:false, fixedIn:\"0:3.10.0-862.el7\", isSrcPack:false, srcPackName:\"\"}} 
defPacks.def.DefinitionID = oval:com.redhat.rhsa:def:20181062, cve.CveID = CVE-2017-15127, defPacks.binpkgFixstat = map[string]oval.fixStat{\"dracut\":oval.fixStat{notFixedYet:false, fixedIn:\"0:033-502.el7_4.1\", isSrcPack:false, srcPackName:\"\"}, \"dracut-config-generic\":oval.fixStat{notFixedYet:false, fixedIn:\"0:033-502.el7_4.1\", isSrcPack:false, srcPackName:\"\"}, \"dracut-config-rescue\":oval.fixStat{notFixedYet:false, fixedIn:\"0:033-502.el7_4.1\", isSrcPack:false, srcPackName:\"\"}, \"dracut-network\":oval.fixStat{notFixedYet:false, fixedIn:\"0:033-502.el7_4.1\", isSrcPack:false, srcPackName:\"\"}, \"kernel\":oval.fixStat{notFixedYet:false, fixedIn:\"0:3.10.0-862.el7\", isSrcPack:false, srcPackName:\"\"}, \"kernel-tools\":oval.fixStat{notFixedYet:false, fixedIn:\"0:3.10.0-862.el7\", isSrcPack:false, srcPackName:\"\"}, \"kernel-tools-libs\":oval.fixStat{notFixedYet:false, fixedIn:\"0:3.10.0-862.el7\", isSrcPack:false, srcPackName:\"\"}} 
defPacks.def.DefinitionID = oval:com.redhat.rhsa:def:20181062, cve.CveID = CVE-2017-17558, defPacks.binpkgFixstat = map[string]oval.fixStat{\"dracut\":oval.fixStat{notFixedYet:false, fixedIn:\"0:033-502.el7_4.1\", isSrcPack:false, srcPackName:\"\"}, \"dracut-config-generic\":oval.fixStat{notFixedYet:false, fixedIn:\"0:033-502.el7_4.1\", isSrcPack:false, srcPackName:\"\"}, \"dracut-config-rescue\":oval.fixStat{notFixedYet:false, fixedIn:\"0:033-502.el7_4.1\", isSrcPack:false, srcPackName:\"\"}, \"dracut-network\":oval.fixStat{notFixedYet:false, fixedIn:\"0:033-502.el7_4.1\", isSrcPack:false, srcPackName:\"\"}, \"kernel\":oval.fixStat{notFixedYet:false, fixedIn:\"0:3.10.0-862.el7\", isSrcPack:false, srcPackName:\"\"}, \"kernel-tools\":oval.fixStat{notFixedYet:false, fixedIn:\"0:3.10.0-862.el7\", isSrcPack:false, srcPackName:\"\"}, \"kernel-tools-libs\":oval.fixStat{notFixedYet:false, fixedIn:\"0:3.10.0-862.el7\", isSrcPack:false, srcPackName:\"\"}} 
defPacks.def.DefinitionID = oval:com.redhat.rhsa:def:20181062, cve.CveID = CVE-2017-7294, defPacks.binpkgFixstat = map[string]oval.fixStat{\"dracut\":oval.fixStat{notFixedYet:false, fixedIn:\"0:033-502.el7_4.1\", isSrcPack:false, srcPackName:\"\"}, \"dracut-config-generic\":oval.fixStat{notFixedYet:false, fixedIn:\"0:033-502.el7_4.1\", isSrcPack:false, srcPackName:\"\"}, \"dracut-config-rescue\":oval.fixStat{notFixedYet:false, fixedIn:\"0:033-502.el7_4.1\", isSrcPack:false, srcPackName:\"\"}, \"dracut-network\":oval.fixStat{notFixedYet:false, fixedIn:\"0:033-502.el7_4.1\", isSrcPack:false, srcPackName:\"\"}, \"kernel\":oval.fixStat{notFixedYet:false, fixedIn:\"0:3.10.0-862.el7\", isSrcPack:false, srcPackName:\"\"}, \"kernel-tools\":oval.fixStat{notFixedYet:false, fixedIn:\"0:3.10.0-862.el7\", isSrcPack:false, srcPackName:\"\"}, \"kernel-tools-libs\":oval.fixStat{notFixedYet:false, fixedIn:\"0:3.10.0-862.el7\", isSrcPack:false, srcPackName:\"\"}} 
defPacks.def.DefinitionID = oval:com.redhat.rhsa:def:20181062, cve.CveID = CVE-2016-8633, defPacks.binpkgFixstat = map[string]oval.fixStat{\"dracut\":oval.fixStat{notFixedYet:false, fixedIn:\"0:033-502.el7_4.1\", isSrcPack:false, srcPackName:\"\"}, \"dracut-config-generic\":oval.fixStat{notFixedYet:false, fixedIn:\"0:033-502.el7_4.1\", isSrcPack:false, srcPackName:\"\"}, \"dracut-config-rescue\":oval.fixStat{notFixedYet:false, fixedIn:\"0:033-502.el7_4.1\", isSrcPack:false, srcPackName:\"\"}, \"dracut-network\":oval.fixStat{notFixedYet:false, fixedIn:\"0:033-502.el7_4.1\", isSrcPack:false, srcPackName:\"\"}, \"kernel\":oval.fixStat{notFixedYet:false, fixedIn:\"0:3.10.0-862.el7\", isSrcPack:false, srcPackName:\"\"}, \"kernel-tools\":oval.fixStat{notFixedYet:false, fixedIn:\"0:3.10.0-862.el7\", isSrcPack:false, srcPackName:\"\"}, \"kernel-tools-libs\":oval.fixStat{notFixedYet:false, fixedIn:\"0:3.10.0-862.el7\", isSrcPack:false, srcPackName:\"\"}} 
defPacks.def.DefinitionID = oval:com.redhat.rhsa:def:20181062, cve.CveID = CVE-2017-13305, defPacks.binpkgFixstat = map[string]oval.fixStat{\"dracut\":oval.fixStat{notFixedYet:false, fixedIn:\"0:033-502.el7_4.1\", isSrcPack:false, srcPackName:\"\"}, \"dracut-config-generic\":oval.fixStat{notFixedYet:false, fixedIn:\"0:033-502.el7_4.1\", isSrcPack:false, srcPackName:\"\"}, \"dracut-config-rescue\":oval.fixStat{notFixedYet:false, fixedIn:\"0:033-502.el7_4.1\", isSrcPack:false, srcPackName:\"\"}, \"dracut-network\":oval.fixStat{notFixedYet:false, fixedIn:\"0:033-502.el7_4.1\", isSrcPack:false, srcPackName:\"\"}, \"kernel\":oval.fixStat{notFixedYet:false, fixedIn:\"0:3.10.0-862.el7\", isSrcPack:false, srcPackName:\"\"}, \"kernel-tools\":oval.fixStat{notFixedYet:false, fixedIn:\"0:3.10.0-862.el7\", isSrcPack:false, srcPackName:\"\"}, \"kernel-tools-libs\":oval.fixStat{notFixedYet:false, fixedIn:\"0:3.10.0-862.el7\", isSrcPack:false, srcPackName:\"\"}} 
defPacks.def.DefinitionID = oval:com.redhat.rhsa:def:20181062, cve.CveID = CVE-2017-15265, defPacks.binpkgFixstat = map[string]oval.fixStat{\"dracut\":oval.fixStat{notFixedYet:false, fixedIn:\"0:033-502.el7_4.1\", isSrcPack:false, srcPackName:\"\"}, \"dracut-config-generic\":oval.fixStat{notFixedYet:false, fixedIn:\"0:033-502.el7_4.1\", isSrcPack:false, srcPackName:\"\"}, \"dracut-config-rescue\":oval.fixStat{notFixedYet:false, fixedIn:\"0:033-502.el7_4.1\", isSrcPack:false, srcPackName:\"\"}, \"dracut-network\":oval.fixStat{notFixedYet:false, fixedIn:\"0:033-502.el7_4.1\", isSrcPack:false, srcPackName:\"\"}, \"kernel\":oval.fixStat{notFixedYet:false, fixedIn:\"0:3.10.0-862.el7\", isSrcPack:false, srcPackName:\"\"}, \"kernel-tools\":oval.fixStat{notFixedYet:false, fixedIn:\"0:3.10.0-862.el7\", isSrcPack:false, srcPackName:\"\"}, \"kernel-tools-libs\":oval.fixStat{notFixedYet:false, fixedIn:\"0:3.10.0-862.el7\", isSrcPack:false, srcPackName:\"\"}} 
defPacks.def.DefinitionID = oval:com.redhat.rhsa:def:20181062, cve.CveID = CVE-2018-6927, defPacks.binpkgFixstat = map[string]oval.fixStat{\"dracut\":oval.fixStat{notFixedYet:false, fixedIn:\"0:033-502.el7_4.1\", isSrcPack:false, srcPackName:\"\"}, \"dracut-config-generic\":oval.fixStat{notFixedYet:false, fixedIn:\"0:033-502.el7_4.1\", isSrcPack:false, srcPackName:\"\"}, \"dracut-config-rescue\":oval.fixStat{notFixedYet:false, fixedIn:\"0:033-502.el7_4.1\", isSrcPack:false, srcPackName:\"\"}, \"dracut-network\":oval.fixStat{notFixedYet:false, fixedIn:\"0:033-502.el7_4.1\", isSrcPack:false, srcPackName:\"\"}, \"kernel\":oval.fixStat{notFixedYet:false, fixedIn:\"0:3.10.0-862.el7\", isSrcPack:false, srcPackName:\"\"}, \"kernel-tools\":oval.fixStat{notFixedYet:false, fixedIn:\"0:3.10.0-862.el7\", isSrcPack:false, srcPackName:\"\"}, \"kernel-tools-libs\":oval.fixStat{notFixedYet:false, fixedIn:\"0:3.10.0-862.el7\", isSrcPack:false, srcPackName:\"\"}} 

I checked dracut with goval-dictionary and found that it has CVE-2017-5715.
Since vinfo(.AffectedPackages) is obtained in the following, it will be added to defPacks.binpkgFixstat from this timing.

vinfo, ok := r.ScannedCves[cve.CveID]

$ goval-dictionary select --by-package redhat 7 dracut x86_64
[]models.Definition{
  models.Definition{
    DefinitionID: "oval:com.redhat.rhba:def:20180042",
    Advisory:     models.Advisory{
      Cves:         []models.Cve{
        models.Cve{
          CveID:      "CVE-2017-5715",
        },
      },
    },
    AffectedPacks: []models.Package{
      models.Package{
        Name:            "dracut",
        Version:         "0:033-502.el7_4.1",
      },
      models.Package{
        Name:            "dracut-caps",
        Version:         "0:033-502.el7_4.1",
      },
      models.Package{
        Name:            "dracut-config-generic",
        Version:         "0:033-502.el7_4.1",
      },
      models.Package{
        Name:            "dracut-config-rescue",
        Version:         "0:033-502.el7_4.1",
      },
      models.Package{
        Name:            "dracut-fips",
        Version:         "0:033-502.el7_4.1",
      },
      models.Package{
        Name:            "dracut-fips-aesni",
        Version:         "0:033-502.el7_4.1",
      },
      models.Package{
        Name:            "dracut-network",
        Version:         "0:033-502.el7_4.1",
      },
      models.Package{
        Name:            "dracut-tools",
        Version:         "0:033-502.el7_4.1",
      },
    },
  },
}

What I want to do is to distribute defPacks.binpkgFixstat to vinfo.AffectedPackages, so I made the following changes.

vuls/oval/redhat.go

Lines 104 to 168 in a591720

func (o RedHatBase) update(r *models.ScanResult, defpacks defPacks) (nCVEs int) {
for _, cve := range defpacks.def.Advisory.Cves {
ovalContent := o.convertToModel(cve.CveID, &defpacks.def)
if ovalContent == nil {
continue
}
vinfo, ok := r.ScannedCves[cve.CveID]
if !ok {
logging.Log.Debugf("%s is newly detected by OVAL: DefID: %s", cve.CveID, defpacks.def.DefinitionID)
vinfo = models.VulnInfo{
CveID: cve.CveID,
Confidences: models.Confidences{models.OvalMatch},
CveContents: models.NewCveContents(*ovalContent),
}
nCVEs++
} else {
cveContents := vinfo.CveContents
if v, ok := vinfo.CveContents[ovalContent.Type]; ok {
for _, vv := range v {
if vv.LastModified.After(ovalContent.LastModified) {
logging.Log.Debugf("%s ignored. DefID: %s ", cve.CveID, defpacks.def.DefinitionID)
} else {
logging.Log.Debugf("%s OVAL will be overwritten. DefID: %s", cve.CveID, defpacks.def.DefinitionID)
}
}
} else {
logging.Log.Debugf("%s also detected by OVAL. DefID: %s", cve.CveID, defpacks.def.DefinitionID)
cveContents = models.CveContents{}
}
vinfo.Confidences.AppendIfMissing(models.OvalMatch)
cveContents[ovalContent.Type] = []models.CveContent{*ovalContent}
vinfo.CveContents = cveContents
}
vinfo.DistroAdvisories.AppendIfMissing(
o.convertToDistroAdvisory(&defpacks.def))
// uniq(vinfo.AffectedPackages[].Name + defPacks.binpkgFixstat(map[string(=package name)]fixStat{}))
collectBinpkgFixstat := defPacks{
binpkgFixstat: map[string]fixStat{},
}
for packName, fixStatus := range defpacks.binpkgFixstat {
collectBinpkgFixstat.binpkgFixstat[packName] = fixStatus
}
for _, pack := range vinfo.AffectedPackages {
if stat, ok := collectBinpkgFixstat.binpkgFixstat[pack.Name]; !ok {
collectBinpkgFixstat.binpkgFixstat[pack.Name] = fixStat{
notFixedYet: pack.NotFixedYet,
fixedIn: pack.FixedIn,
}
} else if stat.notFixedYet {
collectBinpkgFixstat.binpkgFixstat[pack.Name] = fixStat{
notFixedYet: true,
fixedIn: pack.FixedIn,
}
}
}
vinfo.AffectedPackages = collectBinpkgFixstat.toPackStatuses()
vinfo.AffectedPackages.Sort()
r.ScannedCves[cve.CveID] = vinfo
}
return
}

@MaineK00n MaineK00n changed the title [WIP] feat(oval): support new goval-dictionary model feat(oval): support new goval-dictionary model Sep 11, 2021
@MaineK00n MaineK00n requested a review from kotakanbe September 11, 2021 12:20
Copy link
Member

@kotakanbe kotakanbe left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@kotakanbe kotakanbe merged commit 591786f into master Sep 13, 2021
@kotakanbe kotakanbe changed the title feat(oval): support new goval-dictionary model breaking-change(oval): support new goval-dictionary model Sep 13, 2021
@MaineK00n MaineK00n deleted the MaineK00n/change-oval-model branch September 18, 2021 14:03
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants