feat: soft researcher/disclosure misattribution check - #157
Merged
Merged
Conversation
Catches the pattern behind the AVE-2026-00060 and repo-forensics attribution mistakes: researcher field names an AVE maintainer while references contains what reads as the actual external disclosure. Warning only, not a hard failure, some records are genuinely original cataloguing with no external discloser. Tested against four cases before integration: the real mistake, its corrected form, a genuine original record, and an implementation-only reference, all four behave correctly.
3 tasks done
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Adds a warning-only check to
validate_records.pyfor the exact misattribution pattern caught via alexgreensh's correction (see PR #154). Not a hard failure. Tested against four cases before this PR: catches the real mistake, clears the corrected version, and doesn't false-positive on legitimately original records or implementation-only references.Summary
check_researcher_matches_disclosure(): flags a record whereresearcheris an AVE maintainer name (INTERNAL_RESEARCHER_NAMES) whilereferencescontains an entry that reads like the actual primary external disclosure (DISCLOSURE_SIGNAL_WORDS: disclosure, advisory, cve, vulnerability report, responsible disclosure, security research, paper).main()asWARNING [ave_id]: ...output, printed alongside but kept separate from hard failures -- does not incrementtotal_errors, does not affect the exit code. Confirmed:python3 scripts/validate_records.pystill prints "All 76 records valid" and exits 0 even with warnings present.AVE-2026-00063/00064correctly stay silent -- their references are pure crosswalk-gap language, no disclosure-signal words). These 10 are previously-uncaught instances in older batch records (AVE-2026-00003,00013,00026,00029,00039,00047,00052,00053,00054,00056), worth a real follow-up look, not something this PR fixes.Test plan
python3 scripts/validate_records.py-- exits 0, "All 76 records valid" still prints, warnings shown as additional outputpytest tests/ -x -q-- 305 passed