google / osv-scanner

Vulnerability scanner written in Go which uses the data provided by https://osv.dev
https://google.github.io/osv-scanner/
Apache License 2.0
6.16k stars 350 forks source link

Add support for alpine's /lib/apk/db/installed #72

Closed kpcyrd closed 1 year ago

kpcyrd commented 1 year ago
$ osv-scanner --lockfile /lib/apk/db/installed 
could not determine parser for /lib/apk/db/installed

It seems osv.dev has alpine data available so it seems like a good match. :)

questgugou commented 1 year ago

thankyou verymuch

cmaritan commented 1 year ago

Hello @oliverchang and @another-rex ,

In this commit I've added support for apk "installed" file. I'm adding some error management, tests and will soon make a PR

Regards.