Repository navigation
feat: import chisel in scalibrplugin - #2772
Conversation
64e6842 to
8b9aa1d
Compare
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## main #2772 +/- ##
==========================================
+ Coverage 79.19% 79.23% +0.03%
==========================================
Files 121 121
Lines 8185 8185
==========================================
+ Hits 6482 6485 +3
+ Misses 1322 1320 -2
+ Partials 381 380 -1 ☔ View full report in Codecov by Sentry. 🚀 New features to boost your workflow:
|
another-rex
left a comment
There was a problem hiding this comment.
Can you added a e2e test by added a dockerfile that can build a chisel image, which can be scanned by scanner?
|
Added as |
8a3f52e to
9168fb5
Compare
…el-scalibr-plugin # Conflicts: # cmd/osv-scanner/scan/image/__snapshots__/command_test.snap # cmd/osv-scanner/scan/image/testdata/cassettes/TestCommand_OCIImage.yaml # cmd/osv-scanner/scan/image/testdata/cassettes/TestCommand_OCIImage_JSONFormat.yaml # cmd/osv-scanner/scan/source/testdata/cassettes/TestCommand.yaml # cmd/osv-scanner/scan/source/testdata/cassettes/TestCommand_CallAnalysis.yaml # cmd/osv-scanner/scan/source/testdata/cassettes/TestCommand_CommitSupport.yaml # cmd/osv-scanner/scan/source/testdata/cassettes/TestCommand_GithubActions.yaml # cmd/osv-scanner/scan/source/testdata/cassettes/TestCommand_MoreLockfiles.yaml # go.mod # go.sum
|
@zhijie-yang Hmm been trying to make this test pass for a while. The issue seems to be that because the image is not pinned, it's making the test container image that's being scanned is constantly changing. Is there a way we can pin the versions that chisel is adding? |
|
Hey @another-rex , I've modified the Dockerfile and let Chisel pull the packages from a frozen pocket of the Ubuntu archive. Please see if the tests can pass stably. |
osv-scanner 2.4.0 Created-by: HarmonybrewBot Commit-by: HarmonybrewBot Merged-by: HarmonybrewBot Description: Created by `brew bump` --- Created with `brew bump-formula-pr`.<details> <summary>release notes</summary> <pre>### Features: - [Feature #2815](google/osv-scanner#2815) Add support for the CycloneDX 1.7 specification (bumps `cyclonedx-go` to v0.11.0). - [Feature #2799](google/osv-scanner#2799) Enable `.csproj` and Central Package Management (`nugetcpm`) source scanning plugins by default. - [Feature #2871](google/osv-scanner#2871) Extract and parse Alpine OS distro version (e.g. `Alpine:v3.17`, `Alpine:edge`) from PURL `distro` qualifiers to scan packages under their respective Alpine ecosystems. - [Feature #2801](google/osv-scanner#2801) Enable the `swift/packageresolved` plugin by default to support SwiftURL vulnerability scans. - [Feature #2666](google/osv-scanner#2666) Add a Docker-based variant of the pre-commit hook in `.pre-commit-hooks.yaml` to avoid local compilation. - [Feature #2637](google/osv-scanner#2637) Add a new configuration setting `ScanGoModVersion` (disabled by default) to avoid parsing toolchain version directives directly from `go.mod`, preventing misleading warnings. - [Feature #2772](google/osv-scanner#2772) Scan container images built with Canonical Chisel by enabling the `os/chisel` extractor plugin. ### Fixes: - [Bug #2807](google/osv-scanner#2807) Sanitize package name, source, and version fields in the vertical output format to prevent GitHub Actions workflow command injection vulnerabilities from crafted lock files. - [Bug #2876](google/osv-scanner#2876) Improve HTML scan report usability by supporting standard click modifiers (Ctrl/Cmd/middle click) to open vulnerabilities in new tabs, and preserving scroll position when switching tabs. - [Bug #2783](google/osv-scanner#2783) Keep transitive dependency scanning enabled when specifying the `--offline-vulnerabilities` flag. - [Bug #2808](google/osv-scanner#2808) Deduplicate equivalent OSV matcher requests before executing bulk queries to reduce API overhead. - [Bug #2837](google/osv-scanner#2837) Prevent panics during offline matcher scans (e.g. on unsupported `GitHub Actions` ecosystem) by avoiding parsing errors when checking version ranges. - [Bug #2836](google/osv-scanner#2836) Ensure the scanner returns an exit code of `0` when `--help` or `-h` is explicitly requested. ### Misc: - Update Go version to 1.26.4. - Update `osv-scalibr` to `v0.4.6-0.20260612031204-164402d9140e`. - Tag built Docker and GitHub Action images with the major version (e.g. `:v2`) to allow users to pin to a major version (#2857). ## New Contributors * @herdiyana256 made their first contribution in google/osv-scanner#2801 * @zhijie-yang made their first contribution in google/osv-scanner#2772 * @francose made their first contribution in google/osv-scanner#2837 * @rohan-patnaik made their first contribution in google/osv-scanner#2808 * @evilgensec made their first contribution in google/osv-scanner#2807 * @gotgolem made their first contribution in google/osv-scanner#2783 * @Khuzaimx made their first contribution in google/osv-scanner#2857 **Full Changelog**: https://github.com/google/osv-scanner/compare/v2.3.8...v2.4.0</pre> <p>View the full release notes at <a href="https://github.com/google/osv-scanner/releases/tag/v2.4.0">https://github.com/google/osv-scanner/releases/tag/v2.4.0</a>.</p> </details> <hr> See merge request: Harmonybrew/homebrew-core!11903
Description
This PR imports the
os/chiselextractor from the osv-scalibr in thescalibrplugin/presets.goto enable the scanning of container images built with Chisel.The description of
Ubuntu chiseled packagesis added todocs/supported_languages_and_lockfiles.md, which corresponds to the changes of this PR.This PR expects no breaking changes nor regressive UX to be introduced to the OSV-Scanner.
Related pull requests
google/osv-scalibr#764
google/osv-scalibr#2018
P.S. I've run
make refresh-all REBUILD_IMAGES=trueto update the snapshots.FYI: @cjdcordeiro