<feed xmlns='http://www.w3.org/2005/Atom'>
<title>guix.git/guix/cve.scm, branch master</title>
<subtitle>Personal branch of https://git.savannah.gnu.org/cgit/guix.git/ for implementing 'guix deploy'.
</subtitle>
<id>https://git.jakob.space/guix.git/atom?h=master</id>
<link rel='self' href='https://git.jakob.space/guix.git/atom?h=master'/>
<link rel='alternate' type='text/html' href='https://git.jakob.space/guix.git/'/>
<updated>2018-08-25T23:47:40Z</updated>
<entry>
<title>cve: Update feed URL.</title>
<updated>2018-08-25T23:47:40Z</updated>
<author>
<name>Ludovic Courtès</name>
<email>ludo@gnu.org</email>
</author>
<published>2018-08-25T22:10:51Z</published>
<link rel='alternate' type='text/html' href='https://git.jakob.space/guix.git/commit/?id=8a928aa729f31d3409cee8371894fd9a50e9fe8f'/>
<id>urn:sha1:8a928aa729f31d3409cee8371894fd9a50e9fe8f</id>
<content type='text'>
* guix/cve.scm (yearly-feed-uri): Remove "static." from the URL since
the web site now redirects to the URL without "static.".
</content>
</entry>
<entry>
<title>cve: Use 'http-fetch/cached' instead of having custom caching.</title>
<updated>2017-11-16T07:45:15Z</updated>
<author>
<name>Ludovic Courtès</name>
<email>ludo@gnu.org</email>
</author>
<published>2017-11-15T09:23:38Z</published>
<link rel='alternate' type='text/html' href='https://git.jakob.space/guix.git/commit/?id=7482b98120b5e3380129719f13254b90b18553b9'/>
<id>urn:sha1:7482b98120b5e3380129719f13254b90b18553b9</id>
<content type='text'>
That way CVE fetching benefits from 'If-Modified-Since' handling.

* guix/http-client.scm (http-fetch/cached): Add #:write-cache and
 #:cache-miss parameters and honor them.
* guix/cve.scm (%current-year-ttl, %past-year-ttl): Reduce.
(call-with-cve-port): Remove.
(write-cache): New procedure.
(fetch-vulnerabilities): Rewrite in terms of 'http-fetch/cached'.
</content>
</entry>
<entry>
<title>cve: Disable position recording while reading the CVE list.</title>
<updated>2017-09-19T21:58:25Z</updated>
<author>
<name>Ludovic Courtès</name>
<email>ludo@gnu.org</email>
</author>
<published>2017-09-19T19:24:31Z</published>
<link rel='alternate' type='text/html' href='https://git.jakob.space/guix.git/commit/?id=f1b65d0dd964e4c457e660b9289a357447939d93'/>
<id>urn:sha1:f1b65d0dd964e4c457e660b9289a357447939d93</id>
<content type='text'>
* guix/cve.scm (fetch-vulnerabilities)[read*]: New procedure.
Use it in lieu of 'read'.
</content>
</entry>
<entry>
<title>cve: Use a more compact format for the list of package/versions.</title>
<updated>2016-05-27T23:07:12Z</updated>
<author>
<name>Ludovic Courtès</name>
<email>ludo@gnu.org</email>
</author>
<published>2016-05-27T22:44:36Z</published>
<link rel='alternate' type='text/html' href='https://git.jakob.space/guix.git/commit/?id=870bf71eb0983f0f7f7221434db3ff5f785b3b2c'/>
<id>urn:sha1:870bf71eb0983f0f7f7221434db3ff5f785b3b2c</id>
<content type='text'>
On a warm cache, "guix lint -c cve vorbis-tools" goes down
from 6.5s to 2.4s.

* guix/cve.scm (cpe-&gt;package-name): Change to return two values instead
of a pair.
(cpe-&gt;product-alist): New procedure.
(%parse-vulnerability-feed): Use it instead of 'filter-map'.
(fetch-vulnerabilities): Bump sexp format version to 1.
(vulnerabilities-&gt;lookup-proc): Adjust accordingly.  When #:version is
omitted, return a list of vulnerabilities instead of a list of
version/vulnerability pairs.
* tests/cve.scm (%expected-vulnerabilities)
("vulnerabilities-&gt;lookup-proc): Adjust accordingly.
</content>
</entry>
<entry>
<title>cve: Include the 3 previous years of vulnerabilities.</title>
<updated>2016-05-26T21:00:08Z</updated>
<author>
<name>Ludovic Courtès</name>
<email>ludo@gnu.org</email>
</author>
<published>2016-05-26T21:00:08Z</published>
<link rel='alternate' type='text/html' href='https://git.jakob.space/guix.git/commit/?id=3af7a7a879b91c59fcd5a025ac55db2c69da4fb7'/>
<id>urn:sha1:3af7a7a879b91c59fcd5a025ac55db2c69da4fb7</id>
<content type='text'>
* guix/cve.scm (fetch-vulnerabilities): Add 'format' call.
(current-vulnerabilities): Include the 3 previous years.
</content>
</entry>
<entry>
<title>cve: Remove now unnecessary HTTP caching.</title>
<updated>2016-05-23T16:05:46Z</updated>
<author>
<name>Ludovic Courtès</name>
<email>ludo@gnu.org</email>
</author>
<published>2016-05-23T15:46:59Z</published>
<link rel='alternate' type='text/html' href='https://git.jakob.space/guix.git/commit/?id=86cf13033ec23f24665e6dcfafea2e43080f01b0'/>
<id>urn:sha1:86cf13033ec23f24665e6dcfafea2e43080f01b0</id>
<content type='text'>
* guix/cve.scm (call-with-cve-port): Use 'http-fetch' instead of
'http-fetch/cached'.
</content>
</entry>
<entry>
<title>cve: Keep a summarized sexp in cache instead of the full XML.</title>
<updated>2016-05-23T16:05:46Z</updated>
<author>
<name>Ludovic Courtès</name>
<email>ludo@gnu.org</email>
</author>
<published>2016-05-23T15:42:32Z</published>
<link rel='alternate' type='text/html' href='https://git.jakob.space/guix.git/commit/?id=5cdd21c7fec49e99f20f9ec0444ca1b25ae0bac4'/>
<id>urn:sha1:5cdd21c7fec49e99f20f9ec0444ca1b25ae0bac4</id>
<content type='text'>
This avoids ~20s of XML parsing when running 'guix lint -c cve'.

* guix/cve.scm (vulnerability-&gt;sexp, sexp-&gt;vulnerability)
(fetch-vulnerabilities): New procedures.
(current-vulnerabilities): Use 'fetch-vulnerabilities'.
</content>
</entry>
<entry>
<title>cve: Read entire CVE databases for the current year and the past year.</title>
<updated>2016-03-11T15:33:50Z</updated>
<author>
<name>Ludovic Courtès</name>
<email>ludo@gnu.org</email>
</author>
<published>2016-03-11T14:55:57Z</published>
<link rel='alternate' type='text/html' href='https://git.jakob.space/guix.git/commit/?id=6a25e59514f590aa541ec35ba36fd36b2a1dcbc3'/>
<id>urn:sha1:6a25e59514f590aa541ec35ba36fd36b2a1dcbc3</id>
<content type='text'>
The "Modified" database that we were reading is much smaller, but it
only shows CVEs modified over the past week.

* guix/cve.scm (%now, %current-year, %past-year): New variables.
(yearly-feed-uri): New procedure.
(%cve-feed-uri, %ttl): Remove.
(%current-year-ttl, %past-year-ttl): New variables.
(call-with-cve-port): Add 'uri' and 'ttl' parameters and honor them.
Add 'setvbuf' call.
(current-vulnerabilities)[read-vulnerabilities]: New procedure.
Read from both %LAST-YEAR and %CURRENT-YEAR.
</content>
</entry>
<entry>
<title>cve: Make CPE patch level part of the version string.</title>
<updated>2016-03-11T15:33:50Z</updated>
<author>
<name>Ludovic Courtès</name>
<email>ludo@gnu.org</email>
</author>
<published>2016-03-11T09:21:58Z</published>
<link rel='alternate' type='text/html' href='https://git.jakob.space/guix.git/commit/?id=cf557afa2e679f73b93796460dee23d5c5c314c5'/>
<id>urn:sha1:cf557afa2e679f73b93796460dee23d5c5c314c5</id>
<content type='text'>
* guix/cve.scm (%cpe-package-rx): Adjust to account for :PATCH-LEVEL.
(cpe-&gt;package-name): Likewise.
</content>
</entry>
<entry>
<title>Add (guix cve).</title>
<updated>2015-11-26T21:35:01Z</updated>
<author>
<name>Ludovic Courtès</name>
<email>ludo@gnu.org</email>
</author>
<published>2015-11-26T20:52:25Z</published>
<link rel='alternate' type='text/html' href='https://git.jakob.space/guix.git/commit/?id=0eef7551303e3fc855809d84eed8421d2a075cfa'/>
<id>urn:sha1:0eef7551303e3fc855809d84eed8421d2a075cfa</id>
<content type='text'>
* guix/cve.scm, tests/cve-sample.xml, tests/cve.scm: New files.
* Makefile.am (MODULES): Add guix/cve.scm.
(SCM_TESTS): Add tests/cve.scm.
(EXTRA_DIST): Add tests/cve-sample.scm.
</content>
</entry>
</feed>
