Skip to content

feat: Add Support for PURL Scanning and Markdown Report - #50

Merged
arunanshub merged 9 commits into
mainfrom
feat/add-support-pkg-readers
Oct 28, 2025
Merged

feat: Add Support for PURL Scanning and Markdown Report#50
arunanshub merged 9 commits into
mainfrom
feat/add-support-pkg-readers

Conversation

@abhisek

@abhisek abhisek commented Oct 25, 2025

Copy link
Copy Markdown
Member
  • refactor: Support multiple source repo
  • refactor: Organize reporting flags with prefix
  • test: Add package pull test case
  • fix: Add support for code snippet in HTML reporter
  • feat: Add support for markdown reporter

@abhisek
abhisek requested a review from a team October 25, 2025 09:23
@codecov-commenter

codecov-commenter commented Oct 25, 2025

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 56.91906% with 165 lines in your changes missing coverage. Please review.
✅ Project coverage is 20.01%. Comparing base (ffcaff6) to head (c36b1bc).

Files with missing lines Patch % Lines
pkg/reporter/html.go 0.00% 57 Missing ⚠️
pkg/reporter/markdown.go 72.95% 45 Missing and 8 partials ⚠️
cmd/generate.go 0.00% 46 Missing ⚠️
internal/command/package_pull.go 82.97% 4 Missing and 4 partials ⚠️
pkg/reporter/summary.go 0.00% 1 Missing ⚠️
Additional details and impacted files
@@            Coverage Diff             @@
##            main      #50       +/-   ##
==========================================
+ Coverage   3.40%   20.01%   +16.60%     
==========================================
  Files         19       22        +3     
  Lines        880     1239      +359     
==========================================
+ Hits          30      248      +218     
- Misses       843      972      +129     
- Partials       7       19       +12     

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

@github-actions

github-actions Bot commented Oct 25, 2025

Copy link
Copy Markdown

vet Summary Report

This report is generated by vet

Policy Checks

  • ✅ Vulnerability
  • ✅ Malware
  • ✅ License
  • ❌ Popularity
  • ❌ Maintenance
  • ✅ Security Posture
  • ✅ Threats

Malicious Package Analysis

Malicious package analysis was performed using SafeDep Cloud API

Malicious Package Analysis Report
Ecosystem Package Version Status Report
ECOSYSTEM_GO go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc 0.61.0 🔗
ECOSYSTEM_GO google.golang.org/grpc 1.75.0 🔗
ECOSYSTEM_GO golang.org/x/oauth2 0.30.0 🔗
ECOSYSTEM_GO github.com/envoyproxy/go-control-plane/envoy 1.32.4 🔗
ECOSYSTEM_GO go.opentelemetry.io/otel 1.38.0 🔗
ECOSYSTEM_GO go.opentelemetry.io/otel/sdk 1.38.0 🔗
ECOSYSTEM_GO go.opentelemetry.io/otel/sdk/metric 1.38.0 🔗
ECOSYSTEM_GO github.com/zeebo/errs 1.4.0 🔗
ECOSYSTEM_GO github.com/envoyproxy/protoc-gen-validate 1.2.1 🔗
ECOSYSTEM_GO github.com/googleapis/gax-go/v2 2.14.2 🔗
ECOSYSTEM_GO github.com/planetscale/vtprotobuf 0.6.1-0.20240319094008-0393e58bdf10 🔗
ECOSYSTEM_GO go.opentelemetry.io/otel/exporters/otlp/otlptrace 1.38.0 🔗
ECOSYSTEM_GO github.com/cncf/xds/go 0.0.0-20250501225837-2ac532fd4443 🔗
ECOSYSTEM_GO go.yaml.in/yaml/v3 3.0.4 🔗
ECOSYSTEM_GO golang.org/x/sync 0.17.0 🔗
ECOSYSTEM_GO go.opentelemetry.io/proto/otlp 1.7.1 🔗
ECOSYSTEM_GO github.com/google/pprof 0.0.0-20250602020802-c6617b811d0e 🔗
ECOSYSTEM_GO golang.org/x/crypto 0.41.0 🔗
ECOSYSTEM_GO github.com/GoogleCloudPlatform/opentelemetry-operations-go/detectors/gcp 1.29.0 🔗
ECOSYSTEM_GO github.com/go-jose/go-jose/v4 4.1.1 🔗
ECOSYSTEM_GO cloud.google.com/go/monitoring 1.24.2 🔗
ECOSYSTEM_GO cloud.google.com/go/auth 0.16.1 🔗
ECOSYSTEM_GO github.com/spiffe/go-spiffe/v2 2.5.0 🔗
ECOSYSTEM_GO github.com/grpc-ecosystem/grpc-gateway/v2 2.27.2 🔗
ECOSYSTEM_GO github.com/googleapis/enterprise-certificate-proxy 0.3.6 🔗
ECOSYSTEM_GO buf.build/gen/go/safedep/api/protocolbuffers/go 1.36.6-20250705071048-7ad8e6be7c05.1 🔗
ECOSYSTEM_GO golang.org/x/time 0.11.0 🔗
ECOSYSTEM_GO cloud.google.com/go/compute/metadata 0.7.0 🔗
ECOSYSTEM_GO google.golang.org/protobuf 1.36.8 🔗
ECOSYSTEM_GO go.opentelemetry.io/otel/metric 1.38.0 🔗
ECOSYSTEM_GO cloud.google.com/go/auth/oauth2adapt 0.2.8 🔗
ECOSYSTEM_GO cloud.google.com/go/storage 1.55.0 🔗
ECOSYSTEM_GO github.com/google/s2a-go 0.1.9 🔗
ECOSYSTEM_GO github.com/cenkalti/backoff/v5 5.0.3 🔗
ECOSYSTEM_GO github.com/safedep/dry 0.0.0-20251025050813-25b3d2836927 🔗
ECOSYSTEM_GO go.opentelemetry.io/contrib/detectors/gcp 1.36.0 🔗
ECOSYSTEM_GO cloud.google.com/go/iam 1.5.2 🔗
ECOSYSTEM_GO github.com/package-url/packageurl-go 0.1.3 🔗
ECOSYSTEM_GO go.opentelemetry.io/otel/trace 1.38.0 🔗
ECOSYSTEM_GO cloud.google.com/go 0.121.2 🔗
ECOSYSTEM_GO cloud.google.com/go/profiler 0.4.3 🔗
ECOSYSTEM_GO google.golang.org/genproto/googleapis/rpc 0.0.0-20250825161204-c5933d9347a5 🔗
ECOSYSTEM_GO google.golang.org/genproto/googleapis/api 0.0.0-20250825161204-c5933d9347a5 🔗
  • ℹ️ 43 packages have been actively analyzed for malicious behaviour.
  • ✅ No malicious packages found.

Note: Some of the package analysis jobs may still be running.Please check back later. Consider increasing the timeout for better coverage.

Changed Packages

Changed Packages

  • ⚠️ [Go] github.com/google/s2a-go@0.1.9
  • ✅ [Go] github.com/googleapis/gax-go/v2@2.14.2
  • ✅ [Go] go.opentelemetry.io/otel/metric@1.38.0
  • ✅ [Go] cloud.google.com/go/profiler@0.4.3
  • ✅ [Go] github.com/cenkalti/backoff/v5@5.0.3
  • ✅ [Go] go.opentelemetry.io/otel/exporters/otlp/otlptrace@1.38.0
  • ✅ [Go] golang.org/x/sync@0.17.0
  • ✅ [Go] github.com/GoogleCloudPlatform/opentelemetry-operations-go/internal/resourcemapping@0.52.0
  • ✅ [Go] go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc@0.61.0
  • ✅ [Go] github.com/spiffe/go-spiffe/v2@2.5.0
  • ✅ [Go] google.golang.org/grpc@1.75.0
  • ✅ [Go] golang.org/x/oauth2@0.30.0
  • ✅ [Go] github.com/GoogleCloudPlatform/opentelemetry-operations-go/exporter/metric@0.52.0
  • ✅ [Go] buf.build/gen/go/safedep/api/protocolbuffers/go@1.36.6-20250705071048-7ad8e6be7c05.1
  • ✅ [Go] cloud.google.com/go/monitoring@1.24.2
  • ⚠️ [Go] github.com/zeebo/errs@1.4.0
  • ✅ [Go] go.opentelemetry.io/contrib/detectors/gcp@1.36.0
  • ✅ [Go] github.com/google/pprof@0.0.0-20250602020802-c6617b811d0e
  • ✅ [Go] cloud.google.com/go/auth@0.16.1
  • ✅ [Go] google.golang.org/api@0.235.0
  • ✅ [Go] cloud.google.com/go/auth/oauth2adapt@0.2.8
  • ✅ [Go] github.com/GoogleCloudPlatform/opentelemetry-operations-go/detectors/gcp@1.29.0
  • ✅ [Go] go.yaml.in/yaml/v3@3.0.4
  • ✅ [Go] github.com/envoyproxy/go-control-plane/envoy@1.32.4
  • ✅ [Go] go.opentelemetry.io/otel/sdk@1.38.0
  • ⚠️ [Go] github.com/cncf/xds/go@0.0.0-20250501225837-2ac532fd4443
  • ⚠️ [Go] github.com/package-url/packageurl-go@0.1.3
  • ✅ [Go] golang.org/x/time@0.11.0
  • ✅ [Go] cloud.google.com/go/compute/metadata@0.7.0
  • ✅ [Go] cloud.google.com/go/storage@1.55.0
  • ✅ [Go] github.com/grpc-ecosystem/grpc-gateway/v2@2.27.2
  • ✅ [Go] go.opentelemetry.io/otel@1.38.0
  • ⚠️ [Go] github.com/googleapis/enterprise-certificate-proxy@0.3.6
  • ✅ [Go] google.golang.org/genproto/googleapis/api@0.0.0-20250825161204-c5933d9347a5
  • ✅ [Go] google.golang.org/genproto@0.0.0-20250528174236-200df99c418a
  • ✅ [Go] github.com/envoyproxy/protoc-gen-validate@1.2.1
  • ⚠️ [Go] github.com/planetscale/vtprotobuf@0.6.1-0.20240319094008-0393e58bdf10
  • ✅ [Go] golang.org/x/crypto@0.41.0
  • ✅ [Go] google.golang.org/protobuf@1.36.8
  • ✅ [Go] github.com/go-jose/go-jose/v4@4.1.1
  • ✅ [Go] google.golang.org/genproto/googleapis/rpc@0.0.0-20250825161204-c5933d9347a5
  • ✅ [Go] cloud.google.com/go/iam@1.5.2
  • ✅ [Go] go.opentelemetry.io/otel/sdk/metric@1.38.0
  • ⚠️ [Go] github.com/safedep/dry@0.0.0-20251025050813-25b3d2836927
  • ✅ [Go] go.opentelemetry.io/otel/trace@1.38.0
  • ✅ [Go] cloud.google.com/go@0.121.2
  • ✅ [Go] go.opentelemetry.io/proto/otlp@1.7.1
Policy Violations

Packages Violating Policy

[Go] github.com/google/s2a-go@0.1.9 🔗

  • ➡️ Found in manifest go.mod
  • ⚠️ Component appears to be unmaintained

[Go] github.com/zeebo/errs@1.4.0 🔗

  • ➡️ Found in manifest go.mod
  • ⚠️ Component appears to be unmaintained

[Go] github.com/cncf/xds/go@0.0.0-20250501225837-2ac532fd4443 🔗

  • ➡️ Found in manifest go.mod
  • ⚠️ Component appears to be unmaintained

[Go] github.com/package-url/packageurl-go@0.1.3 🔗

  • ➡️ Found in manifest go.mod
  • ⚠️ Component appears to be unmaintained

[Go] github.com/googleapis/enterprise-certificate-proxy@0.3.6 🔗

  • ➡️ Found in manifest go.mod
  • ⚠️ Component appears to be unmaintained

[Go] github.com/planetscale/vtprotobuf@0.6.1-0.20240319094008-0393e58bdf10 🔗

  • ➡️ Found in manifest go.mod
  • ⚠️ Component appears to be unmaintained

[Go] github.com/safedep/dry@0.0.0-20251025050813-25b3d2836927 🔗

  • ➡️ Found in manifest go.mod
  • ⚠️ Component popularity is low by Github stars count
  • ⚡ Use an alternative package that is popular

@abhisek
abhisek marked this pull request as ready for review October 25, 2025 09:28
Copilot AI review requested due to automatic review settings October 25, 2025 09:28
@safedep

safedep Bot commented Oct 25, 2025

Copy link
Copy Markdown

SafeDep Report Summary

Green Malicious Packages Badge Green Vulnerable Packages Badge Green Risky License Badge

Package Details
Package Malware Vulnerability Risky License Report
icon buf.build/gen/go/safedep/api/protocolbuffers/go @ v1.36.6-20250705071048-7ad8e6be7c05.1
go.mod
ok icon
ok icon
ok icon
🔗
icon cloud.google.com/go @ v0.121.2
go.mod
ok icon
ok icon
ok icon
🔗
icon cloud.google.com/go/auth @ v0.16.1
go.mod
ok icon
ok icon
ok icon
🔗
icon cloud.google.com/go/auth/oauth2adapt @ v0.2.8
go.mod
ok icon
ok icon
ok icon
🔗
icon cloud.google.com/go/compute/metadata @ v0.7.0
go.mod
ok icon
ok icon
ok icon
🔗
icon cloud.google.com/go/iam @ v1.5.2
go.mod
ok icon
ok icon
ok icon
🔗
icon cloud.google.com/go/monitoring @ v1.24.2
go.mod
ok icon
ok icon
ok icon
🔗
icon cloud.google.com/go/profiler @ v0.4.3
go.mod
ok icon
ok icon
ok icon
🔗
icon cloud.google.com/go/storage @ v1.55.0
go.mod
ok icon
ok icon
ok icon
🔗
icon github.com/GoogleCloudPlatform/opentelemetry-operations-go/detectors/gcp @ v1.29.0
go.mod
ok icon
ok icon
ok icon
🔗
icon github.com/GoogleCloudPlatform/opentelemetry-operations-go/exporter/metric @ v0.52.0
go.mod
ok icon
ok icon
ok icon
🔗
icon github.com/GoogleCloudPlatform/opentelemetry-operations-go/internal/resourcemapping @ v0.52.0
go.mod
ok icon
ok icon
ok icon
🔗
icon github.com/cenkalti/backoff/v5 @ v5.0.3
go.mod
ok icon
ok icon
ok icon
🔗
icon github.com/cncf/xds/go @ v0.0.0-20250501225837-2ac532fd4443
go.mod
ok icon
ok icon
ok icon
🔗
icon github.com/envoyproxy/go-control-plane/envoy @ v1.32.4
go.mod
ok icon
ok icon
ok icon
🔗
icon github.com/envoyproxy/protoc-gen-validate @ v1.2.1
go.mod
ok icon
ok icon
ok icon
🔗
icon github.com/go-jose/go-jose/v4 @ v4.1.1
go.mod
ok icon
ok icon
ok icon
🔗
icon github.com/google/pprof @ v0.0.0-20250602020802-c6617b811d0e
go.mod
ok icon
ok icon
ok icon
🔗
icon github.com/google/s2a-go @ v0.1.9
go.mod
ok icon
ok icon
ok icon
🔗
icon github.com/googleapis/enterprise-certificate-proxy @ v0.3.6
go.mod
ok icon
ok icon
ok icon
🔗
icon github.com/googleapis/gax-go/v2 @ v2.14.2
go.mod
ok icon
ok icon
ok icon
🔗
icon github.com/grpc-ecosystem/grpc-gateway/v2 @ v2.27.2
go.mod
ok icon
ok icon
ok icon
🔗
icon github.com/package-url/packageurl-go @ v0.1.3
go.mod
ok icon
ok icon
ok icon
🔗
icon github.com/planetscale/vtprotobuf @ v0.6.1-0.20240319094008-0393e58bdf10
go.mod
ok icon
ok icon
ok icon
🔗
icon github.com/safedep/dry @ v0.0.0-20251025050813-25b3d2836927
go.mod
ok icon
ok icon
ok icon
🔗
icon github.com/spiffe/go-spiffe/v2 @ v2.5.0
go.mod
ok icon
ok icon
ok icon
🔗
icon github.com/zeebo/errs @ v1.4.0
go.mod
ok icon
ok icon
ok icon
🔗
icon go.opentelemetry.io/contrib/detectors/gcp @ v1.36.0
go.mod
ok icon
ok icon
ok icon
🔗
icon go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc @ v0.61.0
go.mod
ok icon
ok icon
ok icon
🔗
icon go.opentelemetry.io/otel @ v1.38.0
go.mod
ok icon
ok icon
ok icon
🔗
icon go.opentelemetry.io/otel/exporters/otlp/otlptrace @ v1.38.0
go.mod
ok icon
ok icon
ok icon
🔗
icon go.opentelemetry.io/otel/metric @ v1.38.0
go.mod
ok icon
ok icon
ok icon
🔗
icon go.opentelemetry.io/otel/sdk @ v1.38.0
go.mod
ok icon
ok icon
ok icon
🔗
icon go.opentelemetry.io/otel/sdk/metric @ v1.38.0
go.mod
ok icon
ok icon
ok icon
🔗
icon go.opentelemetry.io/otel/trace @ v1.38.0
go.mod
ok icon
ok icon
ok icon
🔗
icon go.opentelemetry.io/proto/otlp @ v1.7.1
go.mod
ok icon
ok icon
ok icon
🔗
icon go.yaml.in/yaml/v3 @ v3.0.4
go.mod
ok icon
ok icon
ok icon
🔗
icon golang.org/x/crypto @ v0.41.0
go.mod
ok icon
ok icon
ok icon
🔗
icon golang.org/x/oauth2 @ v0.30.0
go.mod
ok icon
ok icon
ok icon
🔗
icon golang.org/x/sync @ v0.17.0
go.mod
ok icon
ok icon
ok icon
🔗
icon golang.org/x/time @ v0.11.0
go.mod
ok icon
ok icon
ok icon
🔗
icon google.golang.org/api @ v0.235.0
go.mod
ok icon
ok icon
ok icon
🔗
icon google.golang.org/genproto/googleapis/api @ v0.0.0-20250825161204-c5933d9347a5
go.mod
ok icon
ok icon
ok icon
🔗
icon google.golang.org/genproto/googleapis/rpc @ v0.0.0-20250825161204-c5933d9347a5
go.mod
ok icon
ok icon
ok icon
🔗
icon google.golang.org/grpc @ v1.75.0
go.mod
ok icon
ok icon
ok icon
🔗
icon google.golang.org/protobuf @ v1.36.8
go.mod
ok icon
ok icon
ok icon
🔗

This report is generated by SafeDep Github App

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull Request Overview

This PR adds support for scanning packages by PURL and introduces a markdown reporter format, alongside improvements to HTML reporting and test coverage.

Key Changes:

  • Added PURL-based package scanning that pulls, caches, and scans remote packages
  • Implemented a markdown report generator with configurable sections and code snippet support
  • Enhanced HTML reporter with improved code snippet handling including truncation and source availability indicators
  • Reorganized CLI flags with --report- prefix for better organization

Reviewed Changes

Copilot reviewed 15 out of 16 changed files in this pull request and generated 2 comments.

Show a summary per file
File Description
cmd/generate.go Added PURL input support, reorganized report flags with --report- prefix, and refactored generation flow
internal/command/package_pull.go New package pulling functionality to fetch and cache packages by PURL
internal/command/package_pull_test.go Comprehensive test coverage for package pull operations
pkg/reporter/markdown.go New markdown reporter implementation with configurable sections
pkg/reporter/markdown_test.go Test suite for markdown reporter functionality
pkg/reporter/snippet.go Shared snippet extraction logic with size limits and truncation support
pkg/reporter/snippet_test.go Test coverage for snippet extraction functionality
pkg/reporter/html.go Enhanced with snippet configuration and improved error handling
pkg/reporter/html_test.go Added tests for enhanced snippet fields
pkg/reporter/templates/report.html Updated template with snippet truncation and unavailability indicators
pkg/reporter/templates/report.md New markdown report template
pkg/reporter/summary.go Updated help message to be format-agnostic
internal/analytics/analytics_test.go Improved error handling in tests
go.mod Updated dependencies
flake.nix New Nix development environment configuration

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment thread internal/command/package_pull.go Outdated
Comment thread pkg/reporter/html.go
abhisek and others added 4 commits October 25, 2025 17:56
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
Signed-off-by: Abhisek Datta <abhisek.datta@gmail.com>
@arunanshub
arunanshub merged commit 1d747df into main Oct 28, 2025
7 of 8 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants