-
Notifications
You must be signed in to change notification settings - Fork 19
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Add tests to see if maven/semver version_matches is right or not. #818
Add tests to see if maven/semver version_matches is right or not. #818
Conversation
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Is migration/
the right place for these tests to live?
Signed-off-by: Jim Crossley <jim@crossleys.org>
Seems to be right.
5bc6f13
to
a3e4687
Compare
with wackadoodle CVEs claiming Maven is semver, along with our wackadoodle elision of actually checking version ranges. And fix all of the above.
@@ -0,0 +1,110 @@ | |||
|
|||
create or replace function mavenver_cmp(left_p text, right_p text) |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
I guess we have to do this logic in the db? Too much potentially returned to post-process? All the SQL makes my eyes bleed on to the vomit I just threw up. 👀 🍴 🤮
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Yep, we want to do it in the DB, so that we can also support suitable pagination.
Else, we have to bring them all back, and scrobble around on the rust side winnowing things out of the version ranges.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Add just a touch of Sriracha, and the bloodvomit will be lovely.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
I was once in a band named "bloodvomit"
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Thanks for the quick turnaround!
/* | ||
TODO: Gilles! | ||
These statuses are *not* reflected in the CSAF regarding the quarkus 3.2.11 SBOM, which is the `sbom_id` from results[1] above. | ||
|
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Create an issue for this?
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
sounds good
Thanks for merging! Your report, your privilege. |
Seems to be right.