tree a2a4c3e37c47f7e20109a648567108cfefc6229f
parent 30913b3f436d15633fa8384631c81e1e54b8c98d
author Markus Kusano <kusano@google.com> 1753300896 +0000
committer Markus Kusano <kusano@google.com> 1754423860 -0700

internal/triage/priority: limit reports used for priority

Updates priority.Analyze to only consider reports in the past when
computing priority. Previously, reports ocurring after the
currently-analyzed report would be used for computing priority. This has
2 symmetric consequence:

(1) Adding new high priority report(s) causes low priority reports in
the past to flip to high priority. This is not what we want since
reports that were low priority should stay low. This is the issue
blocking golang/vulndb#3605.

(2) Adding new low priority reports can flip reports from high to low.

Fixing this logic lets us add new reports for case (1), but it also
means we will detect reports which should have been reviewed. We will
need to cleanup these reports before submitting this change.

  - data/reports/GO-2025-3605.yaml

Fixes golang/vulndb#3605

Change-Id: Iebee68b1df0b168ed2a3f09e6f7473756bfa0199
Reviewed-on: https://go-review.googlesource.com/c/vulndb/+/690255
LUCI-TryBot-Result: Go LUCI <golang-scoped@luci-project-accounts.iam.gserviceaccount.com>
Reviewed-by: Neal Patel <nealpatel@google.com>
