nix-community / vulnix

Vulnerability (CVE) scanner for Nix/NixOS.
BSD 3-Clause "New" or "Revised" License
476 stars 36 forks source link

Optionally enforcing reproducility specifying which NVD archive to use #88

Open aciceri opened 1 year ago

aciceri commented 1 year ago

It would be convenient having a CLI option to specify which NVD archive to use. Indeed I'm running vulnix in a CI pipeline and, after re-running it (same commit), I've realized that the state changed due to vulnix non reproducibility.

@ckauhaus I've seen that you are looking for a new maintainer so I don't know how much time you would spend on reviewing my potential PR, but if my proposal makes sense and you are interested let me know and I'll try working on a PR :)