Closed DmitriyLewen closed 12 months ago
@DmitriyLewen I've removed the Rust
const so we will not make this kind of mistake. If I understand correctly, it is not used outside of GHSA. Please correct me if I'm wrong.
If I understand correctly, it is not used outside of GHSA
You are right. Trivy and Trivy-db don't use this constant. We can remove it.
Thanks for confirming. And I explicitly split GHSA ecosystems and Trivy ecosystems as it was confusing. If it looks good to you, I'll merge this PR.
I explicitly split GHSA ecosystems and Trivy ecosystems as it was confusing
This is a better way than mine. Thanks for the help! Let's merge this PR.
Description
After #345 changes we addув check of ecosystems for OSV - https://github.com/aquasecurity/trivy-db/blob/d5388c99ca492bf0c8822b27a2e5190794543bb5/pkg/vulnsrc/osv/osv.go#L143-L146 GHSA uses
Rust
ecosystem -https://github.com/aquasecurity/trivy-db/blob/d5388c99ca492bf0c8822b27a2e5190794543bb5/pkg/vulnsrc/ghsa/ghsa.go#L32 OSV usesCargo
ecosystem - https://github.com/aquasecurity/trivy-db/blob/d5388c99ca492bf0c8822b27a2e5190794543bb5/pkg/vulnsrc/osv/osv.go#L345-L346That is why we don't save Rust advisories.
Result DB: