Repository navigation
feat(contrib/trivy): pass through Trivy's repository class to models.Package - #2662
Merged
Merged
Conversation
…Package
Since v0.69.0 Trivy skips OS advisory matching for deb packages that it
classifies as third-party from the Maintainer field, and since v0.70.0 for
rpm as well. The exclusion cannot be opted out of, is not tied to
--detection-priority and is reported only in debug logs, but the fact that
a package was never matched survives in the JSON as
Result.Packages[].Repository.Class.
trivy-to-vuls dropped that field, so consumers of the converted scan result
could not tell "no vulnerabilities found" from "never matched". Carry it
over to the new models.Package.RepositoryClass instead.
The field is a string rather than a bool so that the three Trivy states
("", "official", "third-party") stay distinguishable: collapsing official
into unset would keep consumers from acting only on an explicit
third-party mark. json omitempty leaves the output bytes unchanged for
every package without a class, including results from other scanners.
For duplicate OS packages the class of the kept version is used, the way
Name, Version and Arch are already resolved. Language packages are
unaffected: only Trivy's rpm and dpkg analyzers set Repository.Class.
Refs: aquasecurity/trivy#9916
Refs: aquasecurity/trivy#9932
Refs: aquasecurity/trivy#10129
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Contributor
There was a problem hiding this comment.
Copilot review overview
🔵 Needs a closer look
Document the required --list-all-pkgs workflow or provide another path for preserving classifications.
Review effort: Lite
Findings: None
What changed in this PR
Adds Trivy repository classification to converted OS package results while preserving backward-compatible JSON output.
Changes:
- Adds optional
RepositoryClasstomodels.Package. - Propagates Trivy classifications during OS package conversion.
- Adds conversion, deduplication, and serialization tests.
| File | Description |
|---|---|
models/packages.go |
Defines the package classification field. |
models/packages_test.go |
Tests omission of empty classification values. |
contrib/trivy/pkg/converter.go |
Copies Trivy repository classes into OS packages. |
contrib/trivy/pkg/converter_test.go |
Tests propagation, deduplication, and scope. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What did you implement:
trivy-to-vulsnow carries Trivy's repository classification over to the scan result, as a newmodels.Package.RepositoryClassfield holding"","official"or"third-party".Since v0.69.0 (#9932, designed in #9916) Trivy classifies deb packages as third-party from the
Maintainerfield and skips OS advisory matching for them; v0.70.0 (#10129) moved the skip into the commonDetectpath, covering rpm as well. Inpkg/detector/ospkg/driver.DropThirdPartyPackagesthe skip takes no flag or option, and the only trace it leaves is a debug-level log line — so a user reading the report cannot see that a package was excluded. The fact does survive in the JSON, though, asResult.Packages[].Repository.Class.The converter dropped that field and
models.Packagehad no place to put it, so consumers of a converted scan result could not tell "no vulnerabilities found" from "never matched against advisories". This PR passes the mark through unchanged. It adds no detection, reporting or display logic; deciding what to do with a third-party package is left to the consumer.Why a string and not a bool: Trivy has three states, and collapsing
officialinto unset would keep consumers from acting only on an explicit third-party mark. As a string, an unknown future class value also survives the conversion.Type of change
How Has This Been Tested?
TestConvertincontrib/trivy/pkg/converter_test.gogains four table-driven cases:ClassOSPkg propagates Repository.Class to Package— third-party, official and unclassified packages in one result.duplicate packages, Repository.Class of the newer version winsand its reverse-order twin — with the duplicate OS packages that Trivy's dpkg analyzer produces, the kept entry must carry the class of the version that was kept, in either input order.ClassLangPkg ignores Repository.Class— library packages are out of scope, since only the rpm and dpkg analyzers set the field.TestPackage_RepositoryClassOmitEmptyinmodels/packages_test.gopins the backward compatibility below.go test ./...is green locally except for thescannertests that need thevulsio/integrationfixtures, which I could not fetch; they fail in their own setup before reaching any assertion, and this change touches no code they exercise.Backward compatibility
The JSON tag is
repositoryClass,omitempty, so for any package without a class — every package from every scanner other than Trivy, and every Trivy result produced before v0.69.0 — the serialized bytes are unchanged. Readers of older scan result JSON get the zero value"", which is the same "unknown" state Trivy itself uses. No existing field changes meaning, and nothing in vuls reads the new field yet.Scope
Result.Class == os-pkgs).models.Libraryis untouched.Checklist:
You don't have to satisfy all of the following.
make fmtmake test(see the note above: everything but the fixture-gatedscannertests)Is this ready for review?: YES
Reference
🤖 Generated with Claude Code