Documentation
¶
Overview ¶
Package osv manages osv-scanner.toml overrides in vendor/ to prevent non-Go manifests from degrading OpenSSF Scorecard Vulnerability checks.
Index ¶
Constants ¶
View Source
const OverrideName = "osv-scanner.toml"
OverrideName is the filename osv-scanner looks for next to a manifest.
Variables ¶
View Source
var Overrides = []Override{
{
Dir: "vendor/golang.org/x/telemetry",
Manifest: "package-lock.json",
Ecosystem: "npm",
What: "the devDependencies of the web UI x/telemetry serves from its own repository",
},
{
Dir: "vendor/github.com/theupdateframework/go-tuf",
Manifest: "requirements-test.txt",
Ecosystem: "PyPI",
What: "the Python harness go-tuf runs its own conformance tests under",
},
{
Dir: "vendor/github.com/txn2/txeh",
Manifest: "requirements-docs.txt",
Ecosystem: "PyPI",
What: "the MkDocs toolchain that builds txeh's documentation site",
},
{
Dir: "vendor/go.opentelemetry.io/otel",
Manifest: "requirements.txt",
Ecosystem: "PyPI",
What: "the codespell pin otel's own spelling check installs",
},
}
Overrides is the full set of non-Go manifests in vendor/.
Functions ¶
func ForeignManifest ¶
ForeignManifest reports whether name is a dependency manifest for an ecosystem other than Go.
func OverrideContent ¶
OverrideContent renders the osv-scanner.toml for one override.
func VerifyVendor ¶
func VerifyVendor() error
VerifyVendor checks that vendor/ contains all required overrides and no uncovered manifests.
func WriteOverrides ¶
func WriteOverrides() error
WriteOverrides writes every override into vendor/.
Types ¶
Click to show internal directories.
Click to hide internal directories.