-
Notifications
You must be signed in to change notification settings - Fork 188
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
Collect dpkg and rpm source pkg info
This PR adds source package name and source package version information to the Package object data model. It also adds scripts in base.yml for rpm and dpkg package managers to collect source package names and versions. Tern currently reports binary package metadata in its reports. Source packages exist in operating systems like Debian and RedHat and differ from binary packages. Source packages provide all of the necessary files to compile or build a desired piece of software. Binary packages are what get produced as a result of building a source package and are what typically gets installed in an environment. Binary packages can have different names and/or versions as their source package. Source packages are relevant in the context of security scanning as most CVEs are reported by source package name and version. Resolves #1083 Signed-off-by: Rose Judge <rjudge@vmware.com>
- Loading branch information
Showing
5 changed files
with
69 additions
and
6 deletions.
There are no files selected for viewing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters