From 36bff78abc42237dca2f6ffe498c131241a3d952 Mon Sep 17 00:00:00 2001 From: Andrew Nesbitt Date: Tue, 28 Jul 2026 17:22:16 +0100 Subject: [PATCH 1/2] formula: render vulnerabilities from the API JSON Shows a Known vulnerabilities table when the formula's API JSON carries vulnerabilities.open (populated by brew generate-formula-api from Homebrew/advisory-database, Homebrew/brew#23341): each entry links its first upstream id (or the BREW-* id when there is none) to osv.dev/vulnerability/ with severity and truncated summary. When vulnerabilities.patched is non-empty, lists the CVEs Homebrew ships a resolves-annotated patch for. Nothing is rendered for formulae without the field so "no records" is not misread as "no vulnerabilities". --- _layouts/formula.html | 27 +++++++++++++++++++++++++++ 1 file changed, 27 insertions(+) diff --git a/_layouts/formula.html b/_layouts/formula.html index 98e57a304dec..1dbef5bf541a 100644 --- a/_layouts/formula.html +++ b/_layouts/formula.html @@ -263,6 +263,33 @@ {%- endif -%} +{%- if f.vulnerabilities.open.size > 0 %} +

Known vulnerabilities in the current version:

+ + {%- for v in f.vulnerabilities.open -%} + {%- assign vid = v.upstream[0] | default: v.id -%} + + + + + {%- endfor %} +
+ {{ vid | escape }} + {%- if v.severity %} ({{ v.severity | escape }}){%- endif -%} + {{ v.summary | truncate: 100 | escape }}
+

Data from Homebrew/advisory-database. Run brew vulns {{ f.name | escape }} for a live check.

+{%- endif -%} + +{%- if f.vulnerabilities.patched.size > 0 %} +

Homebrew ships patches for: + {%- for v in f.vulnerabilities.patched -%} + {%- assign vid = v.upstream[0] | default: v.id %} + {{ vid | escape }} + {%- unless forloop.last -%}, {% endunless -%} + {%- endfor -%}. +

+{%- endif %} +

Analytics:

{%- for interval in site.analytics.intervals -%} From e96e4b29e8f07b8d222f3b3ac7c5d8b5ea1ffc2b Mon Sep 17 00:00:00 2001 From: Andrew Nesbitt Date: Tue, 28 Jul 2026 17:28:21 +0100 Subject: [PATCH 2/2] formula: guard vulnerabilities blocks on the parent field f.vulnerabilities is absent for formulae with no advisory-database records; verified a fixture without the key builds cleanly and renders neither block. --- _layouts/formula.html | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/_layouts/formula.html b/_layouts/formula.html index 1dbef5bf541a..cf853c6b57f7 100644 --- a/_layouts/formula.html +++ b/_layouts/formula.html @@ -263,7 +263,7 @@
{%- endif -%} -{%- if f.vulnerabilities.open.size > 0 %} +{%- if f.vulnerabilities and f.vulnerabilities.open.size > 0 %}

Known vulnerabilities in the current version:

{%- for v in f.vulnerabilities.open -%} @@ -280,7 +280,7 @@

Data from Homebrew/advisory-database. Run brew vulns {{ f.name | escape }} for a live check.

{%- endif -%} -{%- if f.vulnerabilities.patched.size > 0 %} +{%- if f.vulnerabilities and f.vulnerabilities.patched.size > 0 %}

Homebrew ships patches for: {%- for v in f.vulnerabilities.patched -%} {%- assign vid = v.upstream[0] | default: v.id %}