Skip to content

Remove cve-core dependency - #163

Open
afoote-mitre wants to merge 2 commits into
devfrom
af/remove-cve-core
Open

afoote-mitre wants to merge 2 commits into
devfrom
af/remove-cve-core

Conversation

@afoote-mitre

@afoote-mitre afoote-mitre commented Oct 1, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

Decouple the Search API from cve-core so this repository directly owns its configuration, OpenSearch integration, and query execution.

Our search implementation had evolved beyond the abstractions provided by cve-core. The API already constructed its own /search queries and handled semantic filtering, pagination, deadlines, and response validation. However, accessing the underlying OpenSearch client still required private upstream fields and shared configuration internals. That coupling made upstream changes a potential source of breakage and complicated maintenance.

The dependency also brought unrelated packages, required installation from a GitHub branch, and declared a Node.js engine range incompatible with this repository's Node.js 24 runtime. Removing it narrows the dependency footprint and allows fixes to be implemented and released here without coordinating changes in another repository.

Why Remove cve-core?

  • The Search API already owned most of its search behavior. /search already implemented its own query construction, scoped matching, CPE/version comparisons, semantic post-filtering, pagination, and response handling. Keeping cve-core did not eliminate that application-specific code; it primarily added another layer around configuration and the OpenSearch client.
  • Private upstream internals made the integration fragile. The API accessed fields such as SearchReader._client, _cveIndex, and BasicSearchManager._searchReader, and changed shared SearchProviderSpec state. An upstream implementation change could therefore break the API even without a change to the upstream public interface. Using the official OpenSearch client directly removes that dependency on internal structure.
  • Request execution needs to be controlled here. The API must consistently apply TLS settings, request timeouts, cancellation, readiness checks, rejection of partial search results, and response validation. Owning client creation and execution makes these responsibilities explicit, instead of reaching through upstream wrappers or modifying their transport internals.
  • Unused dependencies increased security exposure and maintenance work. The migration reduces locked production dependency entries from 160 to 100, removing packages such as simple-git, @simple-git/argv-parser, adm-zip, and Axios that are not needed by the API-owned implementation. It also removes the dependency paths responsible for the remaining two critical and two high runtime image findings in the October 8, 2026 local scans after the preceding dependency patches. Those findings came through cve-core; this is local scan evidence, not a deployed-image or Wiz rescan.
  • Dependency management should match this project's runtime. cve-core declared a Node.js engine range that excluded the Node.js 24 runtime used here. Its dependency declaration also pointed to a GitHub branch, although the lockfile pinned a specific commit. Direct registry dependencies make the required libraries explicit, remove that upstream engine mismatch, and avoid carrying unrelated packages and overrides.
  • Maintenance and releases should not depend on changes in another repository. Repository-owned configuration and /webSearch query construction let this team diagnose, fix, and release changes within the Search API. /webSearch remains supported. The tradeoff is maintaining a small, focused configuration adapter and query builder here, rather than retaining a broader dependency whose abstractions no longer fit the API's needs.

Changes and Benefits

Change Primary Files Why It Matters
Instantiate and reuse the official OpenSearch client directly utils/searchProvider.js Removes private-field access and gives the API explicit control over transport settings, cancellation, readiness checks, and response validation.
Introduce a local configuration adapter utils/appConfig.js, server.js, config/ Makes configuration loading and precedence explicit without an upstream wrapper.
Move raw-query construction into this repository utils/webSearchQueryBuilder.js, controllers/searchController.js Makes /webSearch behavior independently maintainable and testable.
Remove unused transitive dependencies and overrides package.json, package-lock.json Reduces locked production dependency entries from 160 to 100, shrinking the dependency maintenance and review burden.
Update documentation and regression coverage README.md, Swagger/OpenAPI files, affected test files Keeps documentation and tests aligned with the API-owned implementation.

@afoote-mitre afoote-mitre changed the title Remove cve-core dependency and own OpenSearch integration Remove cve-core dependency Oct 6, 2026
@afoote-mitre afoote-mitre self-assigned this Oct 6, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant