Resolves #48689 Adds a CPE translation so Firefox Developer Edition on macOS resolves to the standard `mozilla:firefox` product. Without it, `CPEFromSoftware` generates no CPE for the app, so it matches no Firefox CVEs and shows as vulnerability-free — a silent false negative. The root cause is that none of the standard matching paths fit Developer Edition: its bundle identifier `org.mozilla.firefoxdeveloperedition` splits to a product token (`firefoxdeveloperedition`) that has no NVD entry, and the sanitized-name and full-text fallbacks don't resolve to `firefox` either. Regular Firefox works only because its bundle (`org.mozilla.firefox`) splits cleanly to `mozilla`/`firefox`. The fix uses the same translation mechanism the existing Firefox ESR rule uses, mapping the Developer Edition bundle to `product: firefox`, `vendor: mozilla` — with no `sw_edition`, since Developer Edition tracks standard Firefox advisories (ESR is the special case that needs the `esr` edition). Match is on the bundle identifier rather than the display name so it's stable regardless of how the app name is ingested. **Out of scope:** Firefox Nightly (`org.mozilla.nightly`) has the same failure mode but uses pre-release version strings (e.g. `155.0a1`) that don't line up with NVD's per-version Firefox CPEs, so mapping it to `firefox` risks bad matches — it warrants separate handling. Firefox Beta already works today (its bundle is `org.mozilla.firefox`), so it needs no change. **Testing.** Two layers, matching how the codebase already tests CPE rules: - An offline unit test (`TestFirefoxDeveloperEditionTranslation`) loads the real shipped `cpe_translations.json` and asserts Developer Edition translates to `mozilla:firefox` with no `sw_edition`. It needs no CPE dictionary or network, so it runs in the fast suite. - A case in the network-gated `TestCPEFromSoftwareIntegration`, alongside the existing regular-Firefox case, asserts the full CPE string against the live NVD dictionary in CI. It reuses the known-good `105.0.1` Firefox entry. The downstream CPE→CVE step is unchanged and already covered for `mozilla:firefox` by `TestTranslateCPEToCVE`, so no new CVE-matching test is needed. # Checklist for submitter - [x] Changes file added for user-visible changes in `changes/`, `orbit/changes/` or `ee/fleetd-chrome/changes`. See [Changes files](https://github.com/fleetdm/fleet/blob/main/docs/Contributing/guides/committing-changes.md#changes-files) for more information. ## Testing - [x] Added/updated automated tests - [x] QA'd all new/changed functionality manually — ran `TestFirefoxDeveloperEditionTranslation` locally against the shipped rule (passes); the full software→CPE resolution against live NVD data is exercised by the network-gated integration case in CI. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * Improved recognition of Firefox Developer Edition on macOS so it maps to the expected Firefox vulnerability data. * Better handling of version matching for this app, helping scan results stay accurate. <!-- end of auto-generated comment: release notes by coderabbit.ai -->
154 B
154 B
- Fixed a false-negative vulnerability report where Firefox Developer Edition on macOS was not matched to any CVEs because Fleet generated no CPE for it.