Skip to content

[!!!][FEATURE] Type vulnerability analysis as enums - #292

Merged
mteu merged 1 commit into
mainfrom
feature/vuln-analysis
Oct 8, 2026
Merged

mteu merged 1 commit into
mainfrom
feature/vuln-analysis

Conversation

@mteu

@mteu mteu commented Oct 8, 2026

Copy link
Copy Markdown
Owner

This PR introduces three new backed enums in mteu\SbomParser\Entity\Vulnerability\: ImpactAnalysisState, ImpactAnalysisJustification and ImpactAnalysisResponse. They use UPPER_SNAKE case names like the other enums in this repo.

VulnerabilityAnalysis::$state, $justification and $response now use them. $response is list<ImpactAnalysisResponse>|null. A value outside the vocabulary fails the parse. The SbomParseException names every offending path, for example vulnerabilities.2.analysis.response.1. Valinor already does this, and a test now pins it.

🚨 Breaking

The three fields were ?string and string[]|null before. Consumers compare against enum cases, or use ->value where they need the string.

@mteu mteu added the breaking label Oct 8, 2026
@mteu
mteu merged commit 434e84e into main Oct 8, 2026
11 checks passed
@mteu
mteu deleted the feature/vuln-analysis branch October 8, 2026 12:05
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant