The purl was built inside the release loop but used after it, so every
affected package got the last release's distro. Resolved releases also
added their current repository version as a fix, and affected versions
from all releases were merged into one range.
Each release now gets its own package with only its own affected and
fixed versions. Releases with fixed_version "0" are skipped since Debian
uses that for releases that were never affected.
Fixes aboutcode-org#2460
Signed-off-by: Sahil Lenka <sahillenka44@gmail.com>
Fixes #2460
The Debian importer was building the purl inside the release loop and using it after the loop, so every affected package ended up with the last release's distro. On top of that, resolved releases added their current repository version as a fix, and affected versions from every release went into one shared range.
Now each release gets its own affected package with just its own versions:
One side effect worth pointing out: releases that were open with no fix used to produce no package at all, because packages were only created per fixed version. They're now stored as affected.
Checked against the live tracker data for openssl / CVE-2024-0727. Before, it gave 6 fixed versions all tagged distro=trixie. Now it gives bookworm fixed in 3.0.13-1~deb12u1, and forky, sid and trixie each fixed in 3.1.5-1.
I updated test_affected_packages_generation because it expected every package to have a fixed range, which was only true because of this bug. Also added a test covering several releases, including a "0" one and an open one.
I went with skipping "0" releases as described in #2460. Happy to change that if you'd prefer to keep them some other way.