Skip to content

feat(vuln): skip third-party packages in common Detect function - #10129

Merged
knqyf263 merged 5 commits into
aquasecurity:mainfrom
knqyf263:skip-third-party-vuln-scanning
Feb 5, 2026
Merged

knqyf263 merged 5 commits into
aquasecurity:mainfrom
knqyf263:skip-third-party-vuln-scanning

Conversation

@knqyf263

@knqyf263 knqyf263 commented Feb 3, 2026 •

Copy link
Copy Markdown
Collaborator

Description

Move third-party package filtering to the common Detect function in pkg/detector/ospkg/detect.go, ensuring all OS types skip third-party packages uniformly. This prevents false positives when scanning packages from repositories like Docker, NVIDIA, EPEL, or Remi against official OS security advisories.

Changes

  • Add Repository.Class check in common Detect function to filter third-party packages
  • Remove duplicate third-party checks from debian.go and ubuntu.go
  • Remove legacy .remi suffix-based filtering from redhat.go
  • Introduce Detector struct for better testability
  • Add unit tests for package filtering logic

How it works

Third-party packages are identified by the RPM analyzer using a vendor allowlist (osVendors). Packages from unknown vendors (e.g., Remi, EPEL, Docker, NVIDIA) are marked as RepositoryClassThirdParty and skipped during vulnerability scanning.

Caveat

For RPM-based systems, we use an allowlist approach where known vendors are considered official and unknown vendors are treated as third-party. This means if an official package comes from a vendor not in the osVendors list, it will be incorrectly skipped (false negative). However, this risk is mitigated because:

  1. The osVendors list is comprehensive for supported distributions
  2. Adding support for a new distribution requires adding both the vendor and detector

Related issues

Checklist

  • I've read the guidelines for contributing to this repository.
  • I've followed the conventions in the PR title.
  • I've added tests that prove my fix is effective or that my feature works.
  • I've updated the documentation with the relevant information (if needed).
  • I've added usage information (if the PR introduces new options)
  • I've included a "before" and "after" example to the description (if the PR is a user interface change).

Move third-party package filtering to the common Detect function in
pkg/detector/ospkg/detect.go, ensuring all OS types skip third-party
packages uniformly. This prevents false positives when scanning
packages from repositories like Docker, NVIDIA, or other third-party
sources against official OS security advisories.

Changes:
- Add Repository.Class check in common Detect function
- Remove duplicate third-party checks from debian.go and ubuntu.go
- Remove legacy .remi suffix-based filtering from redhat.go
- Remove related test case from redhat_test.go

Closes #10118
@knqyf263 knqyf263 added kind/feature Categorizes issue or PR as related to a new feature. scan/vulnerability Issues relating to vulnerability scanning labels Feb 4, 2026
@github-actions github-actions Bot added the apidiff Indicates Go API changes relevant to library consumers (CLI compatibility may be unaffected) label Feb 4, 2026
@github-actions

github-actions Bot commented Feb 4, 2026 •

Copy link
Copy Markdown
Contributor

📊 API Changes Detected

Semver impact: major

github.com/aquasecurity/trivy/pkg/detector/ospkg
  Incompatible changes:
  - Detect: removed
  - RegisterDriver: removed
  Compatible changes:
  - Detector: added
  - NewDetector: added

@aqua-bot
aqua-bot requested a review from a team February 4, 2026 06:20
@knqyf263 knqyf263 self-assigned this Feb 4, 2026
@knqyf263
knqyf263 requested a review from DmitriyLewen February 4, 2026 11:52
@knqyf263 knqyf263 added the autoready Automatically mark PR as ready for review when all checks pass label Feb 4, 2026
@github-actions
github-actions Bot marked this pull request as ready for review February 4, 2026 12:14
@github-actions github-actions Bot removed the autoready Automatically mark PR as ready for review when all checks pass label Feb 4, 2026

@DmitriyLewen DmitriyLewen left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM
left small comments

Comment thread pkg/detector/ospkg/detect.go Outdated
return false
}
if pkg.Repository.Class == ftypes.RepositoryClassThirdParty {
log.DebugContext(ctx, "Skipping third-party package", log.String("package", pkg.Name))

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

nit:
Won't this be too noisy?
Maybe collect all packages in a slice and output the log once?

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Updated d3a1fd5

Comment thread pkg/scan/ospkg/scan.go Outdated
vulns, eosl, err := ospkgDetector.Detect(ctx, target, opts)
detector, err := ospkgDetector.NewDetector(target)
if err != nil {
return result, false, xerrors.Errorf("failed vulnerability detection of OS packages: %w", err)

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
return result, false, xerrors.Errorf("failed vulnerability detection of OS packages: %w", err)
return result, false, xerrors.Errorf("unable to initialize Detector for OS packages: %w", err)

Refactor the OS package vulnerability detection to use a Detector struct
instead of a package-level function. This enables dependency injection
for testing the package filtering logic.

Changes:
- Add Detector struct with target and driver fields
- Add NewDetector constructor that resolves the driver
- Move Detect to be a method on Detector
- Add export_test.go with NewTestDetector for testing
- Add unit tests for package filtering logic
- Update scan/ospkg to use the new API
@knqyf263

knqyf263 commented Feb 5, 2026

Copy link
Copy Markdown
Collaborator Author

I forgot to update the document.
@DmitriyLewen Can you take another look?
14a485d

Comment thread docs/guide/scanner/vulnerability.md Outdated
In such cases, unrecognized third-party packages will still be scanned against official advisories, which could result in false positives.

Conversely, packages from lesser-known but legitimate OS vendors may be incorrectly classified as third-party and skipped, leading to false negatives.
If you notice such cases, please [report an issue](https://github.com/aquasecurity/trivy/issues/new/choose).

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
If you notice such cases, please [report an issue](https://github.com/aquasecurity/trivy/issues/new/choose).
If you notice such cases, please [create a discussion](https://github.com/aquasecurity/trivy/discussions/new).

Or we can use link to new bug - https://github.com/aquasecurity/trivy/discussions/new?category=bugs

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Done
3226522

hjmcnew pushed a commit to hjmcnew/esphome-configs that referenced this pull request Jul 25, 2026
This PR contains the following updates:

| Package | Type | Update | Change |
|---|---|---|---|
| [aquasec/trivy](https://www.aquasec.com/products/trivy/) ([source](https://github.com/aquasecurity/trivy)) | docker | minor | `0.69.3` → `0.72.0` |

---

### Release Notes

<details>
<summary>aquasecurity/trivy (aquasec/trivy)</summary>

### [`v0.72.0`](https://github.com/aquasecurity/trivy/blob/HEAD/CHANGELOG.md#0720-2026-06-30)

[Compare Source](aquasecurity/trivy@v0.71.2...v0.72.0)

##### ⚠ BREAKING CHANGES

- migrate docker config to dockers\_v2 ([#&#8203;10783](aquasecurity/trivy#10783))

##### Features

- **bottlerocket:** add vulnerability matching for Bottlerocket OS ([#&#8203;10893](aquasecurity/trivy#10893)) ([246ee3c](aquasecurity/trivy@246ee3c))
- **dotnet:** detect bundled runtime in self-contained deployments ([#&#8203;10786](aquasecurity/trivy#10786)) ([bd78842](aquasecurity/trivy@bd78842))
- **java:** detect JAR licenses from packaged LICENSE files ([#&#8203;10856](aquasecurity/trivy#10856)) ([b8a1ccd](aquasecurity/trivy@b8a1ccd))
- **java:** detect JAR licenses from the embedded pom.xml ([#&#8203;10851](aquasecurity/trivy#10851)) ([0a166c3](aquasecurity/trivy@0a166c3))
- **misconf:** Adds CloudFront standard logging v2 support to AVD-AWS-0010 ([#&#8203;10848](aquasecurity/trivy#10848)) ([a848925](aquasecurity/trivy@a848925))
- **secret:** add OpenAI secret detection rules ([#&#8203;10798](aquasecurity/trivy#10798)) ([65e5128](aquasecurity/trivy@65e5128))
- **secret:** support new stateless format for GitHub App installation tokens ([#&#8203;10826](aquasecurity/trivy#10826)) ([e68f3d2](aquasecurity/trivy@e68f3d2))

##### Bug Fixes

- correct format verbs in diagnostic messages ([#&#8203;10805](aquasecurity/trivy#10805)) ([859a933](aquasecurity/trivy@859a933))
- forward ospkg detector options through ospkg.NewScanner ([#&#8203;10811](aquasecurity/trivy#10811)) ([28d44d3](aquasecurity/trivy@28d44d3))
- **image:** deterministic OS package deduplication for images with embedded SBOMs ([#&#8203;10777](aquasecurity/trivy#10777)) ([888911b](aquasecurity/trivy@888911b))
- **image:** lookup origin layer for custom resources in merged layers ([#&#8203;10788](aquasecurity/trivy#10788)) ([dccb128](aquasecurity/trivy@dccb128))
- **misconf:** support github\_repository\_vulnerability\_alerts resource ([#&#8203;10680](aquasecurity/trivy#10680)) ([abb5174](aquasecurity/trivy@abb5174))
- **nodejs:** parse project dependencies from multi-document pnpm-lock.yaml ([#&#8203;10861](aquasecurity/trivy#10861)) ([a10291b](aquasecurity/trivy@a10291b))
- **server:** propagate package repository class in client/server mode ([#&#8203;10874](aquasecurity/trivy#10874)) ([a2777ae](aquasecurity/trivy@a2777ae))
- **spdx:** guard against nil root component in SPDX marshaler ([#&#8203;10771](aquasecurity/trivy#10771)) ([c0654e1](aquasecurity/trivy@c0654e1))
- surface the original analysis error instead of context cancellation ([#&#8203;10793](aquasecurity/trivy#10793)) ([3054b3b](aquasecurity/trivy@3054b3b))
- **terraform:** avoid data race on global getter.Getters in remote module resolver ([#&#8203;10843](aquasecurity/trivy#10843)) ([0aff3fd](aquasecurity/trivy@0aff3fd))
- use random suffix for process temp directory instead of PID ([#&#8203;10431](aquasecurity/trivy#10431)) ([c8d1d0d](aquasecurity/trivy@c8d1d0d))
- **vex:** load VEX documents from within the repository directory ([#&#8203;10820](aquasecurity/trivy#10820)) ([1f56a34](aquasecurity/trivy@1f56a34))
- **vuln:** fall back to UNKNOWN severity when vulnerability details are missing ([#&#8203;10795](aquasecurity/trivy#10795)) ([dfd53cf](aquasecurity/trivy@dfd53cf))

##### Continuous Integration

- migrate docker config to dockers\_v2 ([#&#8203;10783](aquasecurity/trivy#10783)) ([848d135](aquasecurity/trivy@848d135))

### [`v0.71.2`](https://github.com/aquasecurity/trivy/releases/tag/v0.71.2)

[Compare Source](aquasecurity/trivy@v0.71.1...v0.71.2)

#### Changelog

- [`055a5c8`](aquasecurity/trivy@055a5c8) release: v0.71.2 \[release/v0.71] ([#&#8203;10871](aquasecurity/trivy#10871))
- [`875328a`](aquasecurity/trivy@875328a) fix(deps): bump alpine to 3.24.1 \[backport: release/v0.71] ([#&#8203;10870](aquasecurity/trivy#10870))
- [`998f7b3`](aquasecurity/trivy@998f7b3) chore(deps): bump the common group with 4 updates \[backport: release/v0.71] ([#&#8203;10867](aquasecurity/trivy#10867))

### [`v0.71.1`](https://github.com/aquasecurity/trivy/releases/tag/v0.71.1)

[Compare Source](aquasecurity/trivy@v0.71.0...v0.71.1)

#### Changelog

- [`164b383`](aquasecurity/trivy@164b383) release: v0.71.1 \[release/v0.71] ([#&#8203;10818](aquasecurity/trivy#10818))
- [`a72d9a4`](aquasecurity/trivy@a72d9a4) fix(oci): validate artifact filename
- [`3dd9847`](aquasecurity/trivy@3dd9847) fix: forward ospkg detector options through ospkg.NewScanner \[backport: release/v0.71] ([#&#8203;10825](aquasecurity/trivy#10825))
- [`a62cbe4`](aquasecurity/trivy@a62cbe4) fix(vex): load VEX documents from within the repository directory \[backport: release/v0.71] ([#&#8203;10821](aquasecurity/trivy#10821))
- [`43d1d26`](aquasecurity/trivy@43d1d26) fix: surface the original analysis error instead of context cancellation \[backport: release/v0.71] ([#&#8203;10812](aquasecurity/trivy#10812))
- [`ac7696c`](aquasecurity/trivy@ac7696c) ci: expect GitHub App bot as backport PR author \[backport: release/v0.71] ([#&#8203;10815](aquasecurity/trivy#10815))

### [`v0.71.0`](https://github.com/aquasecurity/trivy/blob/HEAD/CHANGELOG.md#0710-2026-06-01)

[Compare Source](aquasecurity/trivy@v0.70.0...v0.71.0)

##### Features

- add WithDriver and WithProvider options to ospkg detector ([#&#8203;10740](aquasecurity/trivy#10740)) ([f8a6ddb](aquasecurity/trivy@f8a6ddb))
- **java:** support \<mirrors> from settings.xml ([#&#8203;10692](aquasecurity/trivy#10692)) ([c080ce3](aquasecurity/trivy@c080ce3))
- **sbom:** support for CycloneDX 1.7 ([#&#8203;10715](aquasecurity/trivy#10715)) ([04f739e](aquasecurity/trivy@04f739e))
- **seal:** add vendor support for language file detection. ([#&#8203;10297](aquasecurity/trivy#10297)) ([b08bf6a](aquasecurity/trivy@b08bf6a))
- **secret:** add a way to customize skipped folders, files and exts ([#&#8203;10550](aquasecurity/trivy#10550)) ([e4325b1](aquasecurity/trivy@e4325b1))
- **secret:** add Azure secret detection rules ([#&#8203;10562](aquasecurity/trivy#10562)) ([69dcd18](aquasecurity/trivy@69dcd18))
- **secret:** add Maven rules to detect passwords and passphrases in settings.xml and settings-security.xml files ([#&#8203;10704](aquasecurity/trivy#10704)) ([9ad901d](aquasecurity/trivy@9ad901d))
- **spdx:** add SHA-512 hash algorithm support to SPDX serializer ([#&#8203;10719](aquasecurity/trivy#10719)) ([f2a1237](aquasecurity/trivy@f2a1237))
- **ubuntu:** detect Ubuntu 26.04 LTS ([#&#8203;10592](aquasecurity/trivy#10592)) ([a61feac](aquasecurity/trivy@a61feac))

##### Bug Fixes

- **cloudformation:** propagate AWS::EC2::Instance MetadataOptions ([#&#8203;10731](aquasecurity/trivy#10731)) ([ac2f3d7](aquasecurity/trivy@ac2f3d7))
- **image:** correctly reconstruct RUN instructions built without BuildKit ([#&#8203;10714](aquasecurity/trivy#10714)) ([519eac9](aquasecurity/trivy@519eac9))
- **java:** surface 429 from a remote Maven repository as a fatal error when scanning pom.xml files ([#&#8203;10693](aquasecurity/trivy#10693)) ([f8fdb93](aquasecurity/trivy@f8fdb93))
- **misconf:** fix rendering of nested values in terraform plan lists ([#&#8203;10746](aquasecurity/trivy#10746)) ([9c1cf65](aquasecurity/trivy@9c1cf65))
- **misconf:** make identifiers in ignore rules case-insensitive ([#&#8203;10375](aquasecurity/trivy#10375)) ([a75a468](aquasecurity/trivy@a75a468))
- **misconf:** prevent path traversal in Terraform filesystem functions ([#&#8203;10664](aquasecurity/trivy#10664)) ([9d91b88](aquasecurity/trivy@9d91b88))
- **misconf:** reject nil plays during playbook parsing ([#&#8203;10273](aquasecurity/trivy#10273)) ([0bc5c6d](aquasecurity/trivy@0bc5c6d))
- **misconf:** skip null cty values in AsMapValue to prevent panic ([#&#8203;10723](aquasecurity/trivy#10723)) ([f080e1e](aquasecurity/trivy@f080e1e))
- **misconf:** skip resources with no after changes ([#&#8203;10352](aquasecurity/trivy#10352)) ([f099dc4](aquasecurity/trivy@f099dc4))
- **nodejs:** handle legacy license formats in npm lockfile parser ([#&#8203;10684](aquasecurity/trivy#10684)) ([451fd99](aquasecurity/trivy@451fd99))
- **nodejs:** silently skip subdirectory package.json files with invalid names ([#&#8203;10609](aquasecurity/trivy#10609)) ([0e4dc66](aquasecurity/trivy@0e4dc66))
- overwrite OS packages PURLs after overwrite OS ([#&#8203;10298](aquasecurity/trivy#10298)) ([39a28ed](aquasecurity/trivy@39a28ed))
- pull instead of clone when test repo already exists ([#&#8203;10636](aquasecurity/trivy#10636)) ([3a2f7fb](aquasecurity/trivy@3a2f7fb))
- **report:** don't produce trailing comma in gitlab.tpl links array ([#&#8203;10728](aquasecurity/trivy#10728)) ([69e78e2](aquasecurity/trivy@69e78e2))
- **secret:** correctly skip secret-scanner config file from scanning ([#&#8203;10666](aquasecurity/trivy#10666)) ([fc1e46f](aquasecurity/trivy@fc1e46f))

### [`v0.70.0`](https://github.com/aquasecurity/trivy/blob/HEAD/CHANGELOG.md#0700-2026-04-16)

[Compare Source](aquasecurity/trivy@v0.69.3...v0.70.0)

##### Features

- **go:** detect version from ELF symbol table for binaries built with -trimpath ([#&#8203;10197](aquasecurity/trivy#10197)) ([7acb5f6](aquasecurity/trivy@7acb5f6))
- **java:** add support for proxy configuration from Maven settings.xml ([#&#8203;10187](aquasecurity/trivy#10187)) ([350fe33](aquasecurity/trivy@350fe33))
- **misconf:** adapt ARM k8s clusters ([#&#8203;9696](aquasecurity/trivy#9696)) ([#&#8203;10125](aquasecurity/trivy#10125)) ([66bdec4](aquasecurity/trivy@66bdec4))
- **misconf:** resolve Azure resources via resource\_id ([#&#8203;10173](aquasecurity/trivy#10173)) ([823f363](aquasecurity/trivy@823f363))
- **misconf:** support for azurerm\_network\_interface\_security\_group\_association  ([#&#8203;10215](aquasecurity/trivy#10215)) ([da94d5f](aquasecurity/trivy@da94d5f))
- **python:** add pylock.toml (PEP 751) parser ([#&#8203;9632](aquasecurity/trivy#9632)) ([1a72b32](aquasecurity/trivy@1a72b32))
- **python:** add pylock.toml support ([#&#8203;10137](aquasecurity/trivy#10137)) ([d0a3f63](aquasecurity/trivy@d0a3f63))
- **server:** include server version info in JSON output for client/server mode ([#&#8203;10075](aquasecurity/trivy#10075)) ([4c46d41](aquasecurity/trivy@4c46d41))
- **ubuntu:** add eol data for 25.10 ([#&#8203;10181](aquasecurity/trivy#10181)) ([2c1f65b](aquasecurity/trivy@2c1f65b))
- **vuln:** skip third-party packages in common Detect function ([#&#8203;10129](aquasecurity/trivy#10129)) ([d6e6331](aquasecurity/trivy@d6e6331))

##### Bug Fixes

- **cyclonedx:** include CVSS v4 vulnerability ratings ([#&#8203;10313](aquasecurity/trivy#10313)) ([2a4dfbf](aquasecurity/trivy@2a4dfbf))
- detected vulnerability fields in azure and mariner detector ([#&#8203;10275](aquasecurity/trivy#10275)) ([77f5cb5](aquasecurity/trivy@77f5cb5))
- **flag:** validate template file extension ([#&#8203;10296](aquasecurity/trivy#10296)) ([20458b8](aquasecurity/trivy@20458b8))
- handle Go 1.26 GOEXPERIMENT version format change ([#&#8203;10351](aquasecurity/trivy#10351)) ([f207ec6](aquasecurity/trivy@f207ec6))
- **java:** Disable overwriting exclusions ([#&#8203;10088](aquasecurity/trivy#10088)) ([9a3e0a8](aquasecurity/trivy@9a3e0a8))
- **misconf:** apply check aliases when filtering results via .trivyignore ([#&#8203;10112](aquasecurity/trivy#10112)) ([b775a1b](aquasecurity/trivy@b775a1b))
- **misconf:** initialize custom annotation field if empty ([#&#8203;10123](aquasecurity/trivy#10123)) ([0f0d6db](aquasecurity/trivy@0f0d6db))
- **python:** handle multiple version specifiers in requirements.txt ([#&#8203;10361](aquasecurity/trivy#10361)) ([4cf4498](aquasecurity/trivy@4cf4498))
- **python:** nil pointer dereference with optional poetry groups without dependencies ([#&#8203;10359](aquasecurity/trivy#10359)) ([12ab3ce](aquasecurity/trivy@12ab3ce))
- remove os.Stdout from wazero module config ([#&#8203;10403](aquasecurity/trivy#10403)) ([bda9710](aquasecurity/trivy@bda9710))
- **report:** set correct sarif ROOTPATH uri when scanning a git repository ([#&#8203;10366](aquasecurity/trivy#10366)) ([e5da6de](aquasecurity/trivy@e5da6de))
- **sbom:** add NOASSERTION for licenseDeclared/licenseConcluded in SPDX non-library packages ([#&#8203;10368](aquasecurity/trivy#10368)) ([33b9d8e](aquasecurity/trivy@33b9d8e))
- **sbom:** preserve Red Hat BuildInfo when scanning SBOMs without layer info ([#&#8203;10378](aquasecurity/trivy#10378)) ([e9e9e8c](aquasecurity/trivy@e9e9e8c))
- **server:** exclude JavaDB and CheckBundle from /version endpoint ([#&#8203;10100](aquasecurity/trivy#10100)) ([b9a8d2d](aquasecurity/trivy@b9a8d2d))
- update PhotonOS feed URL ([#&#8203;10122](aquasecurity/trivy#10122)) ([fa195b4](aquasecurity/trivy@fa195b4))
- use Development category for GoReleaser discussions ([#&#8203;10530](aquasecurity/trivy#10530)) ([7ee3e1e](aquasecurity/trivy@7ee3e1e))

##### Performance Improvements

- **plugin:** optimize directory traversal by replacing filepath.Walk with filepath.WalkDir ([#&#8203;10325](aquasecurity/trivy#10325)) ([d7fb355](aquasecurity/trivy@d7fb355))

</details>

---

### Configuration

📅 **Schedule**: (UTC)

- Branch creation
  - At any time (no schedule defined)
- Automerge
  - At any time (no schedule defined)

🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update again.

---

 - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box

---

This PR has been generated by [Mend Renovate](https://github.com/renovatebot/renovate).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4yNzUuMSIsInVwZGF0ZWRJblZlciI6IjQzLjI3NS4xIiwidGFyZ2V0QnJhbmNoIjoibWFzdGVyIiwibGFiZWxzIjpbXX0=-->

Reviewed-on: https://forgejo.r0fl.cc/hjmcnew/esphome-configs/pulls/13
shino pushed a commit to future-architect/vuls that referenced this pull request Sep 24, 2026
…Package (#2662)

Since v0.69.0 Trivy skips OS advisory matching for deb packages that it
classifies as third-party from the Maintainer field, and since v0.70.0 for
rpm as well. The exclusion cannot be opted out of, is not tied to
--detection-priority and is reported only in debug logs, but the fact that
a package was never matched survives in the JSON as
Result.Packages[].Repository.Class.

trivy-to-vuls dropped that field, so consumers of the converted scan result
could not tell "no vulnerabilities found" from "never matched". Carry it
over to the new models.Package.RepositoryClass instead.

The field is a string rather than a bool so that the three Trivy states
("", "official", "third-party") stay distinguishable: collapsing official
into unset would keep consumers from acting only on an explicit
third-party mark. json omitempty leaves the output bytes unchanged for
every package without a class, including results from other scanners.

For duplicate OS packages the class of the kept version is used, the way
Name, Version and Arch are already resolved. Language packages are
unaffected: only Trivy's rpm and dpkg analyzers set Repository.Class.

Refs: aquasecurity/trivy#9916
Refs: aquasecurity/trivy#9932
Refs: aquasecurity/trivy#10129

Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

apidiff Indicates Go API changes relevant to library consumers (CLI compatibility may be unaffected) kind/feature Categorizes issue or PR as related to a new feature. scan/vulnerability Issues relating to vulnerability scanning

Projects

None yet

Development

Successfully merging this pull request may close these issues.

feat(rpm): skip vulnerability scanning for third-party packages

2 participants