Skip to content

feat: partial OSV snapshot release v3.1.0 - #201

Merged
9batalion merged 1 commit into
mainfrom
feat/partial-osv-release
Jul 25, 2026
Merged

feat: partial OSV snapshot release v3.1.0#201
9batalion merged 1 commit into
mainfrom
feat/partial-osv-release

Conversation

@9batalion

Copy link
Copy Markdown
Owner

This PR ships the explicitly partial OSV vulnerability database as a signed GitHub Release asset.

  • Finalized 243,381 OSV records from a verified prefix of the pinned global OSV all.zip.
  • Profile: osv-partial; completeness: partial-osv-prefix.
  • SQLite: 981,495,808 bytes, integrity ok, FK errors 0.
  • Release ZIP: ~235 MB with detached signed manifest.
  • First-run bootstrap downloads, verifies and activates the pinned snapshot.
  • README/docs disclose partial coverage and the growth path to larger snapshots.

Closes the current partial snapshot milestone.

…signed release artifacts

- Add scripts/finalize_partial_osv_vulndb.py to finalize a verified,
  interrupted OSV prefix as profile=osv-partial / completeness=partial-osv-prefix.
- Finalizer uses isolated working copy, re-derives the prefix into a
  disposable SQLite, and requires identical compact-v1 normalized state.
- Make verifier descriptor-pinned and support partial profile contract.
- Bind bootstrap to expected profile contract; separate release vs installed
  database SHA-256 reporting.
- Add regression tests for replacement-inode-safe cleanup, partial
  finalization, checksum tampering and profile binding.
- Update docs and README to disclose partial coverage and growth path.
- Update DEFAULT_GLOBAL_OSV_RELEASE artifact URLs to v3.1.0 partial release.
@9batalion
9batalion merged commit 8f1a9f4 into main Jul 25, 2026
4 checks passed
@9batalion
9batalion deleted the feat/partial-osv-release branch July 25, 2026 07:02
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant