Skip to content

Instantly share code, notes, and snippets.

View ctron's full-sized avatar
🤖
Please hold the line

Jens Reimann ctron

🤖
Please hold the line
View GitHub Profile

Correlation Test Suite (TC-5639) — Scenario Evaluation

Evaluation of 18 test scenarios (S1–S18) against their referenced Jira tickets and the governing specifications (CSAF v2.0, OSV Schema, VEX consumer requirements, RPM versioning).

S1–S14 from commit 8e614fea (PR #2613). S15–S18 from open PRs #2621, #2625, #2626,

@ctron
ctron / correlation-roadmap.md
Last active September 9, 2026 10:22
Correlation Engine Redesign — Roadmap

Correlation Engine Redesign — Roadmap

What Correlation Is

Correlation is the core value proposition of Trustify: matching advisory data (CSAF, OSV, CVE, NVD) against SBOMs to answer "what vulnerabilities affect my software?"

The system must take a component identifier — a PURL, CPE, or file hash — and determine which advisories assert something about it, what status each advisory

Correlation Engine Scenario Test Results

Scenario Result Notes
S1 FAILED TC-2621: cross-stream matching
S2 FAILED TC-2622: wrong version scheme (golang OCI)
S3 FAILED TC-2623: wrong product matching (hummingbird/curl)
S4 PASS
S5 CDX DATA Upstream CSAF lacks VERS ranges — see S5a
S5 SPDX DATA Upstream CSAF lacks VERS ranges — see S5a