fix: upgrade osv-scanner to v2 and handle v2 output format - #108
Conversation
📊 PR Complexity Assessment: Moderate (Score: 3/5)This PR upgrades osv-scanner from v1 to v2.6.0 in the Dockerfile and adjusts 🔍 Complexity Drivers
🎯 Suggested Attention Areas
|
There was a problem hiding this comment.
The PR is generally sound with no critical defects or security vulnerabilities identified. Three maintainability improvements are recommended: defensively type-checking the parsed OSV JSON before attribute access, pinning the Dockerfile toolchain/scanner versions for reproducible builds, and exercising the validation behavior through the public agent path rather than the private helper.
There was a problem hiding this comment.
Code Review Summary
Total Issues Found: 1
Critical Issues (Bugs): 0
Security Issues: 0
Suggestions: 1
Estimated Review Effort: 1/5
Key Findings:
The PR contains one minor style/convention issue in tests/osv_agent_test.py: a local import json inside a function should be moved to the top of the file alongside the other standard-library imports. No functional, security, or correctness problems were identified.
There was a problem hiding this comment.
Found two minor maintainability suggestions and no critical or security issues. The validator should enforce that every result entry is a dict before returning True, and the v2 regression test should assert exactly one emitted message with the expected title and dna rather than only checking that some message was emitted.
Reviewer Scores for Ostorlab/agent_osv #108Each reviewer who left comments is scored between -10 and +10 based on the overall quality of their review feedback. Total reviewers scored: 2
|
Summary
Upgrades osv-scanner from v1 to v2 (v2.6.0+) to eliminate false-positive vulnerability reports on unpinned packages.
In OSV v1, unpinned dependencies (such as unversioned packages in requirements.txt) were assigned dummy "0.0.0" versions, resulting in dozens of phantom CVE reports. OSV v2 resolves
this by skipping unpinned dependencies.
Additionally, updates _is_valid_osv_result() to handle OSV v2's JSON output structure, which introduces top-level metadata fields (such as "experimental_config").
──────
How It Works
metadata keys (experimental_config) are correctly identified as having no findings.
──────
Key Changes
• Dockerfile: Upgraded installation from github.com/google/osv-scanner/cmd/osv-scanner@v1 to github.com/google/osv-scanner/v2/cmd/osv-scanner@v2.
• agent/osv_agent.py: Updated _is_valid_osv_result() to check not parsed.get("results") to properly handle OSV v2 JSON output.
• tests/osv_agent_test.py: Added unit tests covering v1 and v2 empty result structures, malformed JSON, and populated findings.
──────
Verification
• All 103 unit tests pass (pytest -m "not docker").
• Local verification on unpinned curl dependencies: eliminated all 26 false positives (reported 0 findings).
• Local verification on pinned dependencies (cryptography==3.2.0): confirmed real CVEs are still detected and emitted properly.