/** * CVE Discovery — Queries GitHub Advisory Database for security advisories * with linked fix commits, then extracts vulnerable-to-fixed diffs. * * Uses `gh api` CLI (same as pr-discovery.ts) for auth and rate-limit handling. * Filters by ecosystem (npm, pip, go, etc.) and CVSS severity. */ import type { DiffHunk } from '../learned-rules/types.js'; export interface CVEAdvisory { /** GitHub Advisory Database ID (GHSA-xxxx-xxxx-xxxx). */ readonly ghsaId: string; /** CVE identifier (CVE-2024-xxxxx) if assigned. */ readonly cveId: string | null; /** Short summary of the vulnerability. */ readonly summary: string; /** CVSS v3 severity: critical, high, medium, low. */ readonly severity: 'critical' | 'high' | 'medium' | 'low'; /** CVSS v3 score (0-10). */ readonly cvssScore: number; /** CWE IDs associated with this advisory. */ readonly cwes: string[]; /** Affected ecosystem (npm, pip, go, etc.). */ readonly ecosystem: string; /** Affected package name. */ readonly packageName: string; /** Vulnerable version range. */ readonly vulnerableRange: string; /** Fixed version (patched_versions). */ readonly fixedVersion: string | null; /** References: fix commit URLs, advisory URLs, etc. */ readonly references: string[]; /** ISO timestamp of when the advisory was published. */ readonly publishedAt: string; } export interface CVEFixDiff { readonly advisory: CVEAdvisory; readonly repo: string; readonly commitSha: string; readonly hunks: DiffHunk[]; } export interface CVEDiscoveryConfig { /** Ecosystems to query. Defaults to ['npm']. */ readonly ecosystems?: string[]; /** Minimum CVSS severity. Defaults to 'medium'. */ readonly minSeverity?: 'critical' | 'high' | 'medium' | 'low'; /** Max advisories to fetch per ecosystem. */ readonly maxPerEcosystem?: number; /** Only fetch advisories published after this ISO date. */ readonly publishedAfter?: string; /** Fetch exactly these advisories by GHSA id, bypassing ecosystem discovery. */ readonly ghsaIds?: string[]; } /** * Discover security advisories from the GitHub Advisory Database. * * Queries the global advisories endpoint filtered by ecosystem and severity. * Returns structured advisory objects with CVE ID, CVSS, CWEs, and references. */ export declare function discoverAdvisories(config?: CVEDiscoveryConfig): CVEAdvisory[]; /** * Fetch specific advisories by GHSA id — used for targeted harvesting of * recall-benchmark misses. Unknown ids are skipped with a log line. */ export declare function discoverAdvisoriesByIds(ghsaIds: string[], onLog?: (msg: string) => void): CVEAdvisory[]; /** * Extract repo and commit SHA from advisory references. * Returns the first fix commit found, or null. */ export declare function extractFixCommit(references: readonly string[]): { repo: string; sha: string; } | null; /** * Fetch the diff for a fix commit and parse into typed hunks. * Only includes target files (TS/JS/Python, not tests/declarations). */ export declare function fetchCommitDiff(repo: string, sha: string): DiffHunk[]; /** * Discover advisories and fetch their fix commit diffs. * Returns only advisories with at least one parseable fix diff. */ export declare function discoverCVEsWithDiffs(config?: CVEDiscoveryConfig, onLog?: (msg: string) => void): CVEFixDiff[];