Skip to content

feat: add RPM scan plugin wiring#2790

Open
qkal wants to merge 2 commits into
google:mainfrom
qkal:feat/add-rpm-scan-support
Open

feat: add RPM scan plugin wiring#2790
qkal wants to merge 2 commits into
google:mainfrom
qkal:feat/add-rpm-scan-support

Conversation

@qkal
Copy link
Copy Markdown

@qkal qkal commented May 9, 2026

Summary

Adds OSV-Scalibr's RPM package database extractor to OSV-Scanner's default plugin wiring so RPM databases can be scanned alongside the existing APK and DPKG OS package sources.

This also wires the RPM duplicate-package annotator for artifact scans and adds explicit lockfile parse aliases for common RPM database filenames: rpmdb, rpmdb.sqlite, Packages, and Packages.db.

Fixes #254.

Testing

  • go test ./internal/scalibrplugin ./pkg/osvscanner/...

@qkal qkal marked this pull request as ready for review May 9, 2026 01:56
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Add RPM/Red Hat ecosystem support

1 participant