fix(security): fix CVSS parsing and Claude prompt
OSV returns severity.score as a CVSS vector string, not a number, so unmarshalling into float64 errored and every vuln was dropped. Read it as a string, compute the CVSS v3 base score from the vector, and fall back to the database_specific severity label otherwise. Invoke the analysis via "claude -p" instead of a nonexistent "ask" subcommand (which made the CLI treat "ask" as the prompt), and request strict JSON so recommendations are parsed reliably rather than by substring matching. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01GVbEgdgcC1w6qwSq3zC4kg
This commit is contained in:
@@ -44,7 +44,7 @@ func TestQueryOSVWithMockedServer(t *testing.T) {
|
||||
"severity": [
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": 7.5
|
||||
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
|
||||
}
|
||||
],
|
||||
"references": [
|
||||
|
||||
Reference in New Issue
Block a user