support/scripts/pkg-stats: verified CPE has a known id but not version
authorMatthew Weber <Matthew.Weber@collins.com>
Wed, 19 May 2021 02:46:36 +0000 (21:46 -0500)
committerYann E. MORIN <yann.morin.1998@free.fr>
Wed, 19 May 2021 07:26:50 +0000 (09:26 +0200)
Currently a verified CPE reports the following if versions are not found
 cpe:2.3:a:qemu:qemu:5.2.0:*:*:*:*:*:*:*
 CPE identifier unknown in CPE database (Search)

This patch clarifies the report to state the 'version' is unknown instead
of the 'identifier'.

Cc: Yann E. MORIN <yann.morin.1998@free.fr>
Signed-off-by: Matthew Weber <matthew.weber@collins.com>
Signed-off-by: Yann E. MORIN <yann.morin.1998@free.fr>
support/scripts/pkg-stats

index 0cd3674c52bbd3a44b8136980a0c9c2235c3902f..42c36f7f94458268e6c3c507b1aa758163eabe08 100755 (executable)
@@ -610,7 +610,7 @@ def check_package_cpes(nvd_path, packages):
         if cpedb.find(p.cpeid):
             p.status['cpe'] = ("ok", "verified CPE identifier")
         else:
-            p.status['cpe'] = ("error", "CPE identifier unknown in CPE database")
+            p.status['cpe'] = ("error", "CPE version unknown in CPE database")
 
 
 def calculate_stats(packages):