internal/database: set modification timestamp from git history

Set the "modified" field in OSV reports to the timestamp of the last
change in the git history of the appropriate .yaml.

Update code comments for setDates: Setting the publication date
no longer speeds up generation (since we always pull the git history
for the repo), and this function intentionally does not set the
LastModified field (to avoid potential confusion if a report has
a hardcoded, out-of-date LastModified field.)

Fixes golang/vulndb#50434.

Change-Id: Id5f8009d84f450fc9dc87889fb227be7ea17d575
Reviewed-on: https://go-review.googlesource.com/c/vulndb/+/392539
Trust: Damien Neil <dneil@google.com>
Run-TryBot: Damien Neil <dneil@google.com>
TryBot-Result: Gopher Robot <gobot@golang.org>
Reviewed-by: kokoro <noreply+kokoro@google.com>
Reviewed-by: Jonathan Amsterdam <jba@google.com>
2 files changed
tree: f32259bffbaf056bb5db48f7264df2a9ee27bec9
  1. .github/
  2. cmd/
  3. deploy/
  4. devtools/
  5. doc/
  6. internal/
  7. reports/
  8. terraform/
  9. .gitignore
  10. all_test.go
  11. AUTHORS
  12. checks.bash
  13. CONTRIBUTING.md
  14. CONTRIBUTORS
  15. go.mod
  16. go.sum
  17. LICENSE
  18. PATENTS
  19. README.md
  20. tools_test.go
README.md

The Go Vulnerability Database

This repository contains the reports for the Go Vulnerability Database.

If you are interested accessing data from the Go Vulnerability Database, see x/vuln for information. This repository is only used for adding new vulnerabilities.

Reporting a vulnerability

We are not accepting new vulnerability reports at this time. We will update this README.md once we are ready to receive reports.

License

Unless otherwise noted, the Go source files are distributed under the BSD-style license found in the LICENSE file.

Database entries are distributed under the terms of the CC-BY 4.0 license. See x/vuln for information on how to access these entries.