Skip to content

feat: include CVE and severity info in JSON vulnerability entries (fixes #578)#892

Open
janderik wants to merge 1 commit into
pyupio:mainfrom
janderik:feat/include-cve-json-output
Open

feat: include CVE and severity info in JSON vulnerability entries (fixes #578)#892
janderik wants to merge 1 commit into
pyupio:mainfrom
janderik:feat/include-cve-json-output

Conversation

@janderik

@janderik janderik commented Jul 1, 2026

Copy link
Copy Markdown

Description

The JSON output from safety scan --output json only includes safety's internal vulnerability IDs (e.g. "50885"), making it difficult for users to correlate results with known CVEs.

This PR adds CVE references and CVSSv3 severity information directly into each vulnerability entry in the JSON output, making the report self-contained for programmatic consumption.

Changes

New functions in safety/scan/command.py:

  • _build_vuln_lookup(): Builds a lookup dictionary mapping (package_name, vulnerability_id) to CVE and severity data
  • inject_cve_into_vulnerabilities(): Parses the JSON report and enriches each vulnerability entry with CVE and severity fields

Modified flow in process_report():

  • inject_cve_into_vulnerabilities() is called unconditionally (not behind --detailed_output) so CVE info is always available in JSON output

Example

Before:

json { "id": "50885", "vulnerable_spec": ">=1.5,<2.7.4" }

After:

json { "id": "50885", "vulnerable_spec": ">=1.5,<2.7.4", "CVE": ["CVE-2022-1234"], "severity": { "base_severity": "HIGH", "base_score": 7.5, "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" } }

Related

Previously the JSON output (safety scan --output json) only included
safety vulnerability IDs (e.g. '50885') without CVE references or
severity information, even though the data was available internally.

Now each vulnerability entry in the JSON report includes:
- CVE: list of CVE identifiers associated with the vulnerability
- severity: CVSSv3 severity details (base_severity, vector, base_score)

This addresses issue pyupio#578 and makes the JSON output self-contained
for programmatic consumption without requiring the --detailed_output
flag.

Implementation:
- _build_vuln_lookup(): builds a (package, vuln_id) -> CVE/severity map
- inject_cve_into_vulnerabilities(): enriches each JSON vuln entry
- Called unconditionally (not behind --detailed_output) in process_report()
@coderabbitai

coderabbitai Bot commented Jul 1, 2026

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: b0c387fd-24de-4e47-9477-d4f45f62f572

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Cannot find CVE in JSON output

1 participant