IP Library › Granted Patent US 11,475,135
Granted Patent B2
US 11,475,135 · App. 16/206,531 · Granted Oct 18, 2022

Orchestration of vulnerability scanning and issue tracking for version control technology

Inventors: Adam Konrad Parsons (Brooklyn Park, MN); Karthik Ramesh (Ham Lake, MN); Mercedes Leigh Cox (Falcon Heights, MN)
Assignee: Target Brands, Inc.
G06F21/577G06F8/71G06F11/3604G06F2221/033
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,475,135
App. No.
16/206,531
Filed
Nov 30, 2018
Granted
Oct 18, 2022
Kind
B2
Art Unit
2497
USPC
726/25
Abstract

A computer-implemented method includes scanning changed computer instructions to detect vulnerabilities when the changed computer instructions are committed to a version control repository wherein the changed computer instructions comprise changes to a previous version of computer instructions. A vulnerability associated with an open issue for the previous version of computer instructions is determined to not be present in the vulnerabilities detected in the changed computer instructions and computer instructions are sent to close the open issue automatically based on the determination that the vulnerability is not present in the changed computer instructions.

Claims (62)

1. A computer server comprising:

a memory containing instructions and a database comprising vulnerabilities detected in a previous version of a branch of computer code and vulnerabilities detected in a base branch and a head branch of computer code;

a processor executing the instructions in the memory to perform steps comprising:

receiving vulnerabilities detected in a last-committed version of the branch of computer code;

determining that a vulnerability stored in the database for the previous version of the branch of computer code is not in the received vulnerabilities for the last-committed version of the branch of computer code;

in response, instructing an issue tracker to close an issue opened for the vulnerability for the branch of code;

receiving an indication that a commit of a merge of the head branch into the base branch has been received; and

reading the vulnerabilities detected in the head branch from the database and adding the vulnerabilities detected in the head branch and read from the database to the vulnerabilities stored in the database for the base branch based on a determination that a latest scan of the base branch failed to detect the vulnerabilities in the base branch.

2. The computer server of claim 1 wherein the processor executes the instructions in memory to further perform steps comprising:

determining that a second vulnerability stored in the database for the previous version of the branch of computer code is in the received vulnerabilities for the last-committed version of the branch of computer code; and

in response, instructing an issue tracker to add a comment to an open issue for the second vulnerability for the branch to indicate that the second vulnerability was still present in the last-committed version of the branch of computer code.

3. The computer server of claim 1 wherein the processor executes the instructions in memory to further perform steps comprising:

determining that a third vulnerability stored in the database and marked as a false positive vulnerability is in the received vulnerabilities for the last-committed version of the branch of computer code; and

in response, not opening an issue for the third vulnerability.

4. The computer server of claim 3 wherein the third vulnerability marked as a false positive was never present in any version of the branch of computer code before the last-committed version of the branch of computer-code.

5. The computer server of claim 1 wherein the processor executes the instructions in memory to further perform steps comprising:

receiving an indication that a fourth vulnerability in a first branch of computer code stored in a repository is a false positive vulnerability;

searching for open issues for the false positive vulnerability for other branches of computer code stored in the repository; and

for each found open issue, instructing the issue tracker to close the found open issue.

6. The computer server of claim 1 wherein the processor executes the instructions in memory to further perform steps comprising:

determining that a fifth vulnerability stored in the database for an earlier version of the branch of computer code is in the received vulnerabilities for the last-committed version of the branch of computer code; and

in response, instructing the issue tracker to reopen a closed issue for the vulnerability for the branch of code.

7. A method executed by a processor, the method comprising:

receiving vulnerabilities detected in a last-committed version of a branch of computer code;

determining that a vulnerability stored in a database for a previous version of the branch of computer code is not in the received vulnerabilities for the last-committed version of the branch of computer code;

in response, instructing an issue tracker to close an issue opened for the vulnerability for the branch of code;

receiving an indication that a commit of a merge of a head branch into a base branch has been received; and

reading vulnerabilities detected in the head branch from the database and adding the vulnerabilities detected in the head branch and read from the database to vulnerabilities stored in the database for the base branch based on a determination that a latest scan of the base branch failed to detect the vulnerabilities in the base branch.

8. The method of claim 7 further comprising:

determining that a second vulnerability stored in the database for the previous version of the branch of computer code is in the received vulnerabilities for the last-committed version of the branch of computer code; and

in response, instructing an issue tracker to add a comment to an open issue for the second vulnerability for the branch to indicate that the second vulnerability was still present in the last-committed version of the branch of computer code.

9. The method of claim 7 further comprising:

determining that a third vulnerability stored in the database and marked as a false positive vulnerability is in the received vulnerabilities for the last-committed version of the branch of computer code; and

in response, not opening an issue for the third vulnerability.

10. The method of claim 9 wherein the third vulnerability marked as a false positive was never present in any version of the branch of computer code before the last-committed version of the branch of computer-code.

11. The method of claim 7 further comprising:

receiving an indication that a fourth vulnerability in a first branch of computer code stored in a repository is a false positive vulnerability;

searching for open issues for the false positive vulnerability for other branches of computer code stored in the repository; and

for each found open issue, instructing the issue tracker to close the found open issue.

12. The method of claim 7 further comprising:

determining that a fifth vulnerability stored in the database for an earlier version of the branch of computer code is in the received vulnerabilities for the last-committed version of the branch of computer code; and

in response, instructing the issue tracker to reopen a closed issue for the vulnerability for the branch of code.

13. A non-transitory computer-readable medium containing computer-executable instructions for performing steps comprising:

receiving vulnerabilities detected in a last-committed version of a branch of computer code;

determining that a vulnerability stored in a database for a previous version of the branch of computer code is not in the received vulnerabilities for the last-committed version of the branch of computer code;

in response, instructing an issue tracker to close an issue opened for the vulnerability for the branch of code;

receiving an indication that a commit of a merge of a head branch into a base branch has been received; and

reading vulnerabilities detected in the head branch from the database and adding the vulnerabilities detected in the head branch and read from the database to vulnerabilities stored in the database for the base branch based on a determination that a latest scan of the base branch failed to detect the vulnerabilities in the base branch.

14. The non-transitory computer-readable medium of claim 13 further comprising:

determining that a second vulnerability stored in the database for the previous version of the branch of computer code is in the received vulnerabilities for the last-committed version of the branch of computer code; and

in response, instructing an issue tracker to add a comment to an open issue for the second vulnerability for the branch to indicate that the second vulnerability was still present in the last-committed version of the branch of computer code.

15. The non-transitory computer-readable medium of claim 13 further comprising:

determining that a third vulnerability stored in the database and marked as a false positive vulnerability is in the received vulnerabilities for the last-committed version of the branch of computer code; and

in response, not opening an issue for the third vulnerability.

16. The non-transitory computer-readable medium of claim 15 wherein the third vulnerability marked as a false positive was never present in any version of the branch of computer code before the last-committed version of the branch of computer-code.

17. The non-transitory computer-readable medium of claim 13 further comprising:

receiving an indication that a fourth vulnerability in a first branch of computer code stored in a repository is a false positive vulnerability;

searching for open issues for the false positive vulnerability for other branches of computer code stored in the repository; and

for each found open issue, instructing the issue tracker to close the found open issue.

18. The non-transitory computer-readable medium of claim 13 further comprising:

determining that a fifth vulnerability stored in the database for an earlier version of the branch of computer code is in the received vulnerabilities for the last-committed version of the branch of computer code; and

in response, instructing the issue tracker to reopen a closed issue for the vulnerability for the branch of code.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 3, 2018
From: PARSONS, ADAM KONRAD; RAMESH, KARTHIK; COX, MERCEDES LEIGH
To: TARGET BRANDS, INC.
Reel/Frame 047653/0151 →
Continuity (1)
Related Publication 20200175172A1 · Jun 4, 2020