chainguard-dev / malcontent

#supply #chain #attack #detection
Apache License 2.0
446 stars 31 forks source link

Scanning `-compat` packages breaks scanning #536

Closed egibs closed 5 days ago

egibs commented 3 weeks ago

Scanning -compat packages either fails with an error or outright breaks scanning when looping over other packages.

Investigate and handle these packages more gracefully.

tstromberg commented 1 week ago

Is this still a thing?

egibs commented 1 week ago

I was able to complete an A-Z scan without any issues. There's still an error but it doesn't cause any issues.

I think the root cause is that these files are symlinks and the path they're linked to doesn't exist in the package.