Skip to content

feat(contrib/trivy): pass through Trivy's repository class to models.Package - #2662

Merged
shino merged 1 commit into
masterfrom
feat/2172-trivy-third-party-mark
Sep 24, 2026
Merged

shino merged 1 commit into
masterfrom
feat/2172-trivy-third-party-mark

Conversation

@sadayuki-matsuno

Copy link
Copy Markdown
Collaborator

What did you implement:

trivy-to-vuls now carries Trivy's repository classification over to the scan result, as a new models.Package.RepositoryClass field holding "", "official" or "third-party".

Since v0.69.0 (#9932, designed in #9916) Trivy classifies deb packages as third-party from the Maintainer field and skips OS advisory matching for them; v0.70.0 (#10129) moved the skip into the common Detect path, covering rpm as well. In pkg/detector/ospkg/driver.DropThirdPartyPackages the skip takes no flag or option, and the only trace it leaves is a debug-level log line — so a user reading the report cannot see that a package was excluded. The fact does survive in the JSON, though, as Result.Packages[].Repository.Class.

The converter dropped that field and models.Package had no place to put it, so consumers of a converted scan result could not tell "no vulnerabilities found" from "never matched against advisories". This PR passes the mark through unchanged. It adds no detection, reporting or display logic; deciding what to do with a third-party package is left to the consumer.

Why a string and not a bool: Trivy has three states, and collapsing official into unset would keep consumers from acting only on an explicit third-party mark. As a string, an unknown future class value also survives the conversion.

Type of change

  • New feature (non-breaking change which adds functionality)

How Has This Been Tested?

TestConvert in contrib/trivy/pkg/converter_test.go gains four table-driven cases:

  • ClassOSPkg propagates Repository.Class to Package — third-party, official and unclassified packages in one result.
  • duplicate packages, Repository.Class of the newer version wins and its reverse-order twin — with the duplicate OS packages that Trivy's dpkg analyzer produces, the kept entry must carry the class of the version that was kept, in either input order.
  • ClassLangPkg ignores Repository.Class — library packages are out of scope, since only the rpm and dpkg analyzers set the field.

TestPackage_RepositoryClassOmitEmpty in models/packages_test.go pins the backward compatibility below.

CGO_ENABLED=0 GOEXPERIMENT=jsonv2 go test ./contrib/trivy/... ./models/...
CGO_ENABLED=0 GOEXPERIMENT=jsonv2 go vet ./contrib/trivy/... ./models/...
go mod tidy   # no diff

go test ./... is green locally except for the scanner tests that need the vulsio/integration fixtures, which I could not fetch; they fail in their own setup before reaching any assertion, and this change touches no code they exercise.

Backward compatibility

The JSON tag is repositoryClass,omitempty, so for any package without a class — every package from every scanner other than Trivy, and every Trivy result produced before v0.69.0 — the serialized bytes are unchanged. Readers of older scan result JSON get the zero value "", which is the same "unknown" state Trivy itself uses. No existing field changes meaning, and nothing in vuls reads the new field yet.

Scope

  • OS packages only (Result.Class == os-pkgs). models.Library is untouched.
  • Only the converter writes the field; other scanners leave it empty.

Checklist:

You don't have to satisfy all of the following.

  • Write tests
  • Write documentation
  • Check that there aren't other open pull requests for the same issue/feature
  • Format your source code by make fmt
  • Pass the test by make test (see the note above: everything but the fixture-gated scanner tests)
  • Provide verification config / commands
  • Enable "Allow edits from maintainers" for this PR
  • Update the messages below

Is this ready for review?: YES

Reference

🤖 Generated with Claude Code

…Package

Since v0.69.0 Trivy skips OS advisory matching for deb packages that it
classifies as third-party from the Maintainer field, and since v0.70.0 for
rpm as well. The exclusion cannot be opted out of, is not tied to
--detection-priority and is reported only in debug logs, but the fact that
a package was never matched survives in the JSON as
Result.Packages[].Repository.Class.

trivy-to-vuls dropped that field, so consumers of the converted scan result
could not tell "no vulnerabilities found" from "never matched". Carry it
over to the new models.Package.RepositoryClass instead.

The field is a string rather than a bool so that the three Trivy states
("", "official", "third-party") stay distinguishable: collapsing official
into unset would keep consumers from acting only on an explicit
third-party mark. json omitempty leaves the output bytes unchanged for
every package without a class, including results from other scanners.

For duplicate OS packages the class of the kept version is used, the way
Name, Version and Arch are already resolved. Language packages are
unaffected: only Trivy's rpm and dpkg analyzers set Repository.Class.

Refs: aquasecurity/trivy#9916
Refs: aquasecurity/trivy#9932
Refs: aquasecurity/trivy#10129

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@shino
shino marked this pull request as ready for review September 24, 2026 02:14
Copilot AI lite review requested due to automatic review settings September 24, 2026 02:14

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

Document the required --list-all-pkgs workflow or provide another path for preserving classifications.

Review effort: Lite
Findings: None

What changed in this PR

Adds Trivy repository classification to converted OS package results while preserving backward-compatible JSON output.

Changes:

  • Adds optional RepositoryClass to models.Package.
  • Propagates Trivy classifications during OS package conversion.
  • Adds conversion, deduplication, and serialization tests.
File Description
models/​packages.go Defines the package classification field.
models/​packages_test.go Tests omission of empty classification values.
contrib/​trivy/​pkg/​converter.go Copies Trivy repository classes into OS packages.
contrib/​trivy/​pkg/​converter_test.go Tests propagation, deduplication, and scope.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@shino shino left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🎊

@shino
shino merged commit cf2dbba into master Sep 24, 2026
8 checks passed
@shino
shino deleted the feat/2172-trivy-third-party-mark branch September 24, 2026 03:34
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants