Repository navigation
Remove cve-core dependency - #163
Open
afoote-mitre wants to merge 2 commits into
Open
afoote-mitre wants to merge 2 commits into
afoote-mitre wants to merge 2 commits into
Conversation
afoote-mitre
force-pushed
the
af/remove-cve-core
branch
from
October 8, 2026 13:27
cd5d6b3 to
85af5c1
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Decouple the Search API from
cve-coreso this repository directly owns its configuration, OpenSearch integration, and query execution.Our search implementation had evolved beyond the abstractions provided by
cve-core. The API already constructed its own/searchqueries and handled semantic filtering, pagination, deadlines, and response validation. However, accessing the underlying OpenSearch client still required private upstream fields and shared configuration internals. That coupling made upstream changes a potential source of breakage and complicated maintenance.The dependency also brought unrelated packages, required installation from a GitHub branch, and declared a Node.js engine range incompatible with this repository's Node.js 24 runtime. Removing it narrows the dependency footprint and allows fixes to be implemented and released here without coordinating changes in another repository.
Why Remove cve-core?
/searchalready implemented its own query construction, scoped matching, CPE/version comparisons, semantic post-filtering, pagination, and response handling. Keepingcve-coredid not eliminate that application-specific code; it primarily added another layer around configuration and the OpenSearch client.SearchReader._client,_cveIndex, andBasicSearchManager._searchReader, and changed sharedSearchProviderSpecstate. An upstream implementation change could therefore break the API even without a change to the upstream public interface. Using the official OpenSearch client directly removes that dependency on internal structure.simple-git,@simple-git/argv-parser,adm-zip, and Axios that are not needed by the API-owned implementation. It also removes the dependency paths responsible for the remaining two critical and two high runtime image findings in the October 8, 2026 local scans after the preceding dependency patches. Those findings came throughcve-core; this is local scan evidence, not a deployed-image or Wiz rescan.cve-coredeclared a Node.js engine range that excluded the Node.js 24 runtime used here. Its dependency declaration also pointed to a GitHub branch, although the lockfile pinned a specific commit. Direct registry dependencies make the required libraries explicit, remove that upstream engine mismatch, and avoid carrying unrelated packages and overrides./webSearchquery construction let this team diagnose, fix, and release changes within the Search API./webSearchremains supported. The tradeoff is maintaining a small, focused configuration adapter and query builder here, rather than retaining a broader dependency whose abstractions no longer fit the API's needs.Changes and Benefits
utils/searchProvider.jsutils/appConfig.js,server.js,config/utils/webSearchQueryBuilder.js,controllers/searchController.js/webSearchbehavior independently maintainable and testable.package.json,package-lock.jsonREADME.md, Swagger/OpenAPI files, affected test files