Skip to content

feat: import chisel in scalibrplugin - #2772

Merged
another-rex merged 12 commits into
google:mainfrom
zhijie-yang:ROCKS-2010/add-chisel-scalibr-plugin
May 20, 2026
Merged

another-rex merged 12 commits into
google:mainfrom
zhijie-yang:ROCKS-2010/add-chisel-scalibr-plugin

Conversation

@zhijie-yang

Copy link
Copy Markdown
Contributor

Description

This PR imports the os/chisel extractor from the osv-scalibr in the scalibrplugin/presets.go to enable the scanning of container images built with Chisel.

The description of Ubuntu chiseled packages is added to docs/supported_languages_and_lockfiles.md, which corresponds to the changes of this PR.

This PR expects no breaking changes nor regressive UX to be introduced to the OSV-Scanner.

Related pull requests

google/osv-scalibr#764
google/osv-scalibr#2018

P.S. I've run make refresh-all REBUILD_IMAGES=true to update the snapshots.

FYI: @cjdcordeiro

@another-rex
another-rex force-pushed the ROCKS-2010/add-chisel-scalibr-plugin branch from 64e6842 to 8b9aa1d Compare May 7, 2026 03:58
@codecov-commenter

codecov-commenter commented May 7, 2026 •

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 79.23%. Comparing base (4e36a74) to head (4e6f75a).
⚠️ Report is 1 commits behind head on main.

Additional details and impacted files
@@            Coverage Diff             @@
##             main    #2772      +/-   ##
==========================================
+ Coverage   79.19%   79.23%   +0.03%     
==========================================
  Files         121      121              
  Lines        8185     8185              
==========================================
+ Hits         6482     6485       +3     
+ Misses       1322     1320       -2     
+ Partials      381      380       -1     

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@another-rex another-rex left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Can you added a e2e test by added a dockerfile that can build a chisel image, which can be scanned by scanner?

@zhijie-yang

Copy link
Copy Markdown
Contributor Author

Added as cmd/osv-scanner/scan/image/testdata/test-chisel.Dockerfile.

@zhijie-yang
zhijie-yang requested a review from another-rex May 7, 2026 19:27
@another-rex
another-rex force-pushed the ROCKS-2010/add-chisel-scalibr-plugin branch from 8a3f52e to 9168fb5 Compare May 8, 2026 00:29
another-rex and others added 5 commits May 18, 2026 12:11
…el-scalibr-plugin

# Conflicts:
#	cmd/osv-scanner/scan/image/__snapshots__/command_test.snap
#	cmd/osv-scanner/scan/image/testdata/cassettes/TestCommand_OCIImage.yaml
#	cmd/osv-scanner/scan/image/testdata/cassettes/TestCommand_OCIImage_JSONFormat.yaml
#	cmd/osv-scanner/scan/source/testdata/cassettes/TestCommand.yaml
#	cmd/osv-scanner/scan/source/testdata/cassettes/TestCommand_CallAnalysis.yaml
#	cmd/osv-scanner/scan/source/testdata/cassettes/TestCommand_CommitSupport.yaml
#	cmd/osv-scanner/scan/source/testdata/cassettes/TestCommand_GithubActions.yaml
#	cmd/osv-scanner/scan/source/testdata/cassettes/TestCommand_MoreLockfiles.yaml
#	go.mod
#	go.sum
@another-rex

another-rex commented May 19, 2026 •

Copy link
Copy Markdown
Collaborator

@zhijie-yang Hmm been trying to make this test pass for a while. The issue seems to be that because the image is not pinned, it's making the test container image that's being scanned is constantly changing. Is there a way we can pin the versions that chisel is adding?

@zhijie-yang

Copy link
Copy Markdown
Contributor Author

Hey @another-rex , I've modified the Dockerfile and let Chisel pull the packages from a frozen pocket of the Ubuntu archive. Please see if the tests can pass stably.

@another-rex
another-rex merged commit 57b8b78 into google:main May 20, 2026
18 checks passed
social4hyq pushed a commit to social4hyq/homebrew-core that referenced this pull request Sep 20, 2026
osv-scanner 2.4.0

Created-by: HarmonybrewBot
Commit-by: HarmonybrewBot
Merged-by: HarmonybrewBot
Description: Created by `brew bump`

---

Created with `brew bump-formula-pr`.<details>
  <summary>release notes</summary>
  <pre>### Features:

- [Feature #2815](google/osv-scanner#2815) Add support for the CycloneDX 1.7 specification (bumps `cyclonedx-go` to v0.11.0).
- [Feature #2799](google/osv-scanner#2799) Enable `.csproj` and Central Package Management (`nugetcpm`) source scanning plugins by default.
- [Feature #2871](google/osv-scanner#2871) Extract and parse Alpine OS distro version (e.g. `Alpine:v3.17`, `Alpine:edge`) from PURL `distro` qualifiers to scan packages under their respective Alpine ecosystems.
- [Feature #2801](google/osv-scanner#2801) Enable the `swift/packageresolved` plugin by default to support SwiftURL vulnerability scans.
- [Feature #2666](google/osv-scanner#2666) Add a Docker-based variant of the pre-commit hook in `.pre-commit-hooks.yaml` to avoid local compilation.
- [Feature #2637](google/osv-scanner#2637) Add a new configuration setting `ScanGoModVersion` (disabled by default) to avoid parsing toolchain version directives directly from `go.mod`, preventing misleading warnings.
- [Feature #2772](google/osv-scanner#2772) Scan container images built with Canonical Chisel by enabling the `os/chisel` extractor plugin.

### Fixes:

- [Bug #2807](google/osv-scanner#2807) Sanitize package name, source, and version fields in the vertical output format to prevent GitHub Actions workflow command injection vulnerabilities from crafted lock files.
- [Bug #2876](google/osv-scanner#2876) Improve HTML scan report usability by supporting standard click modifiers (Ctrl/Cmd/middle click) to open vulnerabilities in new tabs, and preserving scroll position when switching tabs.
- [Bug #2783](google/osv-scanner#2783) Keep transitive dependency scanning enabled when specifying the `--offline-vulnerabilities` flag.
- [Bug #2808](google/osv-scanner#2808) Deduplicate equivalent OSV matcher requests before executing bulk queries to reduce API overhead.
- [Bug #2837](google/osv-scanner#2837) Prevent panics during offline matcher scans (e.g. on unsupported `GitHub Actions` ecosystem) by avoiding parsing errors when checking version ranges.
- [Bug #2836](google/osv-scanner#2836) Ensure the scanner returns an exit code of `0` when `--help` or `-h` is explicitly requested.

### Misc:

- Update Go version to 1.26.4.
- Update `osv-scalibr` to `v0.4.6-0.20260612031204-164402d9140e`.
- Tag built Docker and GitHub Action images with the major version (e.g. `:v2`) to allow users to pin to a major version (#2857).

## New Contributors
* @herdiyana256 made their first contribution in google/osv-scanner#2801
* @zhijie-yang made their first contribution in google/osv-scanner#2772
* @francose made their first contribution in google/osv-scanner#2837
* @rohan-patnaik made their first contribution in google/osv-scanner#2808
* @evilgensec made their first contribution in google/osv-scanner#2807
* @gotgolem made their first contribution in google/osv-scanner#2783
* @Khuzaimx made their first contribution in google/osv-scanner#2857

**Full Changelog**: https://github.com/google/osv-scanner/compare/v2.3.8...v2.4.0</pre>
  <p>View the full release notes at <a href="https://github.com/google/osv-scanner/releases/tag/v2.4.0">https://github.com/google/osv-scanner/releases/tag/v2.4.0</a>.</p>
</details>
<hr>

See merge request: Harmonybrew/homebrew-core!11903
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants