Skip to content

feat: soft researcher/disclosure misattribution check - #157

Merged
chaksaray merged 1 commit into
developfrom
feat/researcher-disclosure-check
Aug 9, 2026
Merged

chaksaray merged 1 commit into
developfrom
feat/researcher-disclosure-check

Conversation

@chaksaray

Copy link
Copy Markdown
Contributor

Adds a warning-only check to validate_records.py for the exact misattribution pattern caught via alexgreensh's correction (see PR #154). Not a hard failure. Tested against four cases before this PR: catches the real mistake, clears the corrected version, and doesn't false-positive on legitimately original records or implementation-only references.

Summary

  • check_researcher_matches_disclosure(): flags a record where researcher is an AVE maintainer name (INTERNAL_RESEARCHER_NAMES) while references contains an entry that reads like the actual primary external disclosure (DISCLOSURE_SIGNAL_WORDS: disclosure, advisory, cve, vulnerability report, responsible disclosure, security research, paper).
  • Wired into main() as WARNING [ave_id]: ... output, printed alongside but kept separate from hard failures -- does not increment total_errors, does not affect the exit code. Confirmed: python3 scripts/validate_records.py still prints "All 76 records valid" and exits 0 even with warnings present.
  • Run against the live corpus: 10 warnings fired, none on the records already fixed in fix: researcher field attribution rule and worked example #154 (AVE-2026-00063/00064 correctly stay silent -- their references are pure crosswalk-gap language, no disclosure-signal words). These 10 are previously-uncaught instances in older batch records (AVE-2026-00003, 00013, 00026, 00029, 00039, 00047, 00052, 00053, 00054, 00056), worth a real follow-up look, not something this PR fixes.

Test plan

  • python3 scripts/validate_records.py -- exits 0, "All 76 records valid" still prints, warnings shown as additional output
  • pytest tests/ -x -q -- 305 passed

Catches the pattern behind the AVE-2026-00060 and repo-forensics
attribution mistakes: researcher field names an AVE maintainer while
references contains what reads as the actual external disclosure.
Warning only, not a hard failure, some records are genuinely original
cataloguing with no external discloser. Tested against four cases
before integration: the real mistake, its corrected form, a genuine
original record, and an implementation-only reference, all four
behave correctly.
@chaksaray
chaksaray merged commit 33ade7a into develop Aug 9, 2026
6 checks passed
@chaksaray
chaksaray deleted the feat/researcher-disclosure-check branch August 9, 2026 00:49
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant