Skip to content

Instantly share code, notes, and snippets.

@ctron
Created September 10, 2026 11:29
Show Gist options
  • Select an option

  • Save ctron/9bd615b73c0bac543915a6ba1b3e55ac to your computer and use it in GitHub Desktop.

Select an option

Save ctron/9bd615b73c0bac543915a6ba1b3e55ac to your computer and use it in GitHub Desktop.

Correlation Engine Scenario Test Results

Scenario Result Notes
S1 FAILED TC-2621: cross-stream matching
S2 FAILED TC-2622: wrong version scheme (golang OCI)
S3 FAILED TC-2623: wrong product matching (hummingbird/curl)
S4 PASS
S5 CDX DATA Upstream CSAF lacks VERS ranges — see S5a
S5 SPDX DATA Upstream CSAF lacks VERS ranges — see S5a
S5a PASS
S6 PASS
S7 PASS
S8 CDX DATA Upstream CSAF lacks VERS ranges — see S8a
S8 SPDX DATA Upstream CSAF lacks VERS ranges — see S8a
S8a PASS
S9 FAILED TC-2625: substream filtering
S10 DATA Versionless PURLs + no VERS ranges — see S12a
S11 FAILED TC-2626: bare-affected substream
S12 PASS
S12a PASS
S13 PASS
S14 FAILED TC-2627: product-status version filter
S16 FAILED TC-2628: cross-scheme PURL
S17 FAILED TC-2629: cross-product OCP

9 passing, 5 DATA (upstream advisory issue, covered by "a" variants), 7 failing (engine issues).

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment