How to Answer “What’s Affected?” in Open Source @FIRSTdotorg
How to Answer “What’s Affected?” in Open Source  @FIRSTdotorg
Uploaded May 2026 | Updated September 2026, 4 hours ago
Jess Lowe (Google, AU), Rex Pan (Google, AU)

A scalable "alert on artifact" workflow for vulnerability management requires precise and accurate data on which code versions are affected. This is already challenging for linear versioning but becomes significantly more difficult when dealing with non-linear Git graphs. What exactly do "introduced" and "fixed" commits communicate about the vulnerable commits? How do intermediate branches, merges, and forks complicate this picture? We will explore all scenarios encountered while developing the OSV database, offering real-world examples and the corresponding solutions implemented in the OSV-Schema. Attendees will learn how these solutions can help accurately identify vulnerabilities within their dependencies.

---

Jess Lowe is a Software Engineer on the Open Source Vulnerabilities (OSV) project within Google’s Open Source Security Team. Recently, she's been deep in the weeds of bulk CVE conversion, designing the logic and heuristics required to turn ambiguous security records into actionable, machine-readable data.

Rex Pan is a Software Engineer Tech Lead on the Open Source Vulnerabilities (OSV) team and the Google Open Source Security team. His current work concentrates on enhancing developer workflows for addressing and remediating vulnerabilities within their Open Source Software (OSS) dependencies.
How to Answer “What’s Affected?” in Open SourceSysmon Deep Dive: Real Detection Scenarios You Can ReproduceThe PR3TACK Initiative: Building the World’s First Preemptive Tactics & Countermeasures KnowledgebasGuardians of the HypervisorBest Practices for Data Privacy Breach Response: Lessons Learned from Social Media Case StudiesThe Ontology for SOC Creation Assistance and Replication (OSCAR)Panel: Peak Performance Under Pressure: Building Cross-Functional Resilience in Incident ResponseYou Need Some Neurosparkle In Your SOCNavigating the Threat Actor Maze: A Tool for Mapping Names, Families and InsightsStepping up the ENISAs role in Support of EU Vulnerability ServicesFrom Zero to Prepared: Implementing a Weekly Incident Response Drill ProgramIndicator Message eXchange (IMX): Enabling Structured Cyber Threat Intelligence Sharing
FIRST |

How to Answer “What’s Affected?” in Open Source

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER