Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
45 changes: 40 additions & 5 deletions cmd/osv-scanner/scan/image/__snapshots__/command_test.snap
Original file line number Diff line number Diff line change
Expand Up @@ -341,7 +341,8 @@ Package Ubuntu:20.04/shadow/1:4.8.1-1ubuntu5.20.04.5 has been filtered out becau
Package Ubuntu:20.04/perl/5.30.0-9ubuntu0.5 has been filtered out because: Just want to test only unimportant vulns
Package Ubuntu:20.04/tar/1.30+dfsg-7ubuntu0.20.04.4 has been filtered out because: Just want to test only unimportant vulns
Package Ubuntu:20.04/util-linux/2.34-0.1ubuntu9.6 has been filtered out because: Just want to test only unimportant vulns
Filtered 37 ignored package/s from the scan.
Package Ubuntu:20.04/zlib/1:1.2.11.dfsg-2ubuntu1.5 has been filtered out because: Just want to test only unimportant vulns
Filtered 38 ignored package/s from the scan.

Container Scanning Result (Ubuntu 20.04.6 LTS):
Total 0 packages affected by 0 known vulnerabilities (0 Critical, 0 High, 0 Medium, 0 Low, 0 Unknown) from 1 ecosystem.
Expand Down Expand Up @@ -398,7 +399,8 @@ Package Ubuntu:20.04/shadow/1:4.8.1-1ubuntu5.20.04.5 has been filtered out becau
Package Ubuntu:20.04/perl/5.30.0-9ubuntu0.5 has been filtered out because: Just want to test only unimportant vulns
Package Ubuntu:20.04/tar/1.30+dfsg-7ubuntu0.20.04.4 has been filtered out because: Just want to test only unimportant vulns
Package Ubuntu:20.04/util-linux/2.34-0.1ubuntu9.6 has been filtered out because: Just want to test only unimportant vulns
Filtered 37 ignored package/s from the scan.
Package Ubuntu:20.04/zlib/1:1.2.11.dfsg-2ubuntu1.5 has been filtered out because: Just want to test only unimportant vulns
Filtered 38 ignored package/s from the scan.

Container Scanning Result (Ubuntu 20.04.6 LTS):
Total 0 packages affected by 0 known vulnerabilities (0 Critical, 0 High, 0 Medium, 0 Low, 0 Unknown) from 1 ecosystem.
Expand Down Expand Up @@ -426,7 +428,7 @@ You can also view the full vulnerability list in your terminal with: `osv-scanne
Scanning local image tarball "./testdata/test-ubuntu.tar"

Container Scanning Result (Ubuntu 22.04.5 LTS):
Total 22 packages affected by 42 known vulnerabilities (2 Critical, 12 High, 23 Medium, 3 Low, 2 Unknown) from 1 ecosystem.
Total 23 packages affected by 43 known vulnerabilities (2 Critical, 13 High, 23 Medium, 3 Low, 2 Unknown) from 1 ecosystem.
19 vulnerabilities can be fixed.


Expand Down Expand Up @@ -458,6 +460,7 @@ Ubuntu:22.04
| tar | 1.34+dfsg-1ubuntu0.1.22.04.2 | No fix available | 1 | tar | # 4 Layer | ubuntu |
| util-linux | 1:2.37.2-4ubuntu3.4 | No fix available | 1 | bsdutils | # 4 Layer | ubuntu |
| util-linux | 2.37.2-4ubuntu3.4 | No fix available | 1 | libblkid1... (6) | # 4 Layer | ubuntu |
| zlib | 1:1.2.11.dfsg-2ubuntu9.2 | No fix available | 1 | zlib1g | # 4 Layer | ubuntu |
+----------------+------------------------------+-------------------------+------------+-------------------------+------------------+---------------+

Hiding 5 number of vulnerabilities deemed unimportant, use --all-vulns to show them.
Expand All @@ -474,7 +477,7 @@ You can also view the full vulnerability list in your terminal with: `osv-scanne
Scanning local image tarball "./testdata/test-ubuntu.tar"

Container Scanning Result (Ubuntu 22.04.5 LTS):
Total 22 packages affected by 42 known vulnerabilities (2 Critical, 12 High, 23 Medium, 3 Low, 2 Unknown) from 1 ecosystem.
Total 23 packages affected by 43 known vulnerabilities (2 Critical, 13 High, 23 Medium, 3 Low, 2 Unknown) from 1 ecosystem.
19 vulnerabilities can be fixed.


Expand Down Expand Up @@ -506,6 +509,7 @@ Ubuntu:22.04
| tar | 1.34+dfsg-1ubuntu0.1.22.04.2 | No fix available | 1 | tar | # 4 Layer | ubuntu |
| util-linux | 1:2.37.2-4ubuntu3.4 | No fix available | 1 | bsdutils | # 4 Layer | ubuntu |
| util-linux | 2.37.2-4ubuntu3.4 | No fix available | 1 | libblkid1... (6) | # 4 Layer | ubuntu |
| zlib | 1:1.2.11.dfsg-2ubuntu9.2 | No fix available | 1 | zlib1g | # 4 Layer | ubuntu |
+----------------+------------------------------+-------------------------+------------+-------------------------+------------------+---------------+

Filtered Vulnerabilities:
Expand Down Expand Up @@ -541,7 +545,7 @@ failed to load image from tarball with path "../../testdata/locks-manyoci-image/
Scanning local image tarball "./testdata/test-ubuntu-with-packages.tar"

Container Scanning Result (Ubuntu 22.04.5 LTS):
Total 22 packages affected by 42 known vulnerabilities (2 Critical, 12 High, 23 Medium, 3 Low, 2 Unknown) from 1 ecosystem.
Total 23 packages affected by 43 known vulnerabilities (2 Critical, 13 High, 23 Medium, 3 Low, 2 Unknown) from 1 ecosystem.
19 vulnerabilities can be fixed.


Expand Down Expand Up @@ -573,6 +577,7 @@ Ubuntu:22.04
| tar | 1.34+dfsg-1ubuntu0.1.22.04.2 | No fix available | 1 | tar | # 4 Layer | ubuntu |
| util-linux | 1:2.37.2-4ubuntu3.4 | No fix available | 1 | bsdutils | # 4 Layer | ubuntu |
| util-linux | 2.37.2-4ubuntu3.4 | No fix available | 1 | libblkid1... (6) | # 4 Layer | ubuntu |
| zlib | 1:1.2.11.dfsg-2ubuntu9.2 | No fix available | 1 | zlib1g | # 4 Layer | ubuntu |
+----------------+------------------------------+-------------------------+------------+-------------------------+------------------+---------------+

Hiding 5 number of vulnerabilities deemed unimportant, use --all-vulns to show them.
Expand Down Expand Up @@ -3614,6 +3619,21 @@ Scanning local image tarball "./testdata/test-node_modules-npm-full.tar"
"vulnerabilities": [
"UBUNTU-CVE-2025-14104"
]
},
{
"package": {
"name": "zlib",
"os_package_name": "zlib1g",
"version": "1:1.2.11.dfsg-2ubuntu9.2",
"ecosystem": "Ubuntu:22.04",
"image_origin_details": {
"index": 4
}
},
"groups": 1,
"vulnerabilities": [
"UBUNTU-CVE-2025-14847"
]
}
]
}
Expand Down Expand Up @@ -4542,6 +4562,21 @@ Scanning local image tarball "./testdata/test-ubuntu.tar"
"vulnerabilities": [
"UBUNTU-CVE-2025-14104"
]
},
{
"package": {
"name": "zlib",
"os_package_name": "zlib1g",
"version": "1:1.2.11.dfsg-2ubuntu9.2",
"ecosystem": "Ubuntu:22.04",
"image_origin_details": {
"index": 4
}
},
"groups": 1,
"vulnerabilities": [
"UBUNTU-CVE-2025-14847"
]
}
]
}
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -683,7 +683,7 @@ interactions:
proto: HTTP/1.1
proto_major: 1
proto_minor: 1
content_length: 7587
content_length: 7442
host: api.osv.dev
body: |
{
Expand Down Expand Up @@ -1065,13 +1065,6 @@ interactions:
"name": "ubuntu-keyring"
},
"version": "2020.02.11.4"
},
{
"package": {
"ecosystem": "Ubuntu:20.04",
"name": "zlib"
},
"version": "1:1.2.11.dfsg-2ubuntu1.5"
}
]
}
Expand All @@ -1086,7 +1079,7 @@ interactions:
proto: HTTP/2.0
proto_major: 2
proto_minor: 0
content_length: 252
content_length: 249
body: |
{
"results": [
Expand Down Expand Up @@ -1150,13 +1143,12 @@ interactions:
{},
{},
{},
{},
{}
]
}
headers:
Content-Length:
- "252"
- "249"
Content-Type:
- application/json
status: 200 OK
Expand All @@ -1167,7 +1159,7 @@ interactions:
proto: HTTP/1.1
proto_major: 1
proto_minor: 1
content_length: 7587
content_length: 7442
host: api.osv.dev
body: |
{
Expand Down Expand Up @@ -1549,13 +1541,6 @@ interactions:
"name": "ubuntu-keyring"
},
"version": "2020.02.11.4"
},
{
"package": {
"ecosystem": "Ubuntu:20.04",
"name": "zlib"
},
"version": "1:1.2.11.dfsg-2ubuntu1.5"
}
]
}
Expand All @@ -1570,7 +1555,7 @@ interactions:
proto: HTTP/2.0
proto_major: 2
proto_minor: 0
content_length: 252
content_length: 249
body: |
{
"results": [
Expand Down Expand Up @@ -1634,13 +1619,12 @@ interactions:
{},
{},
{},
{},
{}
]
}
headers:
Content-Length:
- "252"
- "249"
Content-Type:
- application/json
status: 200 OK
Expand Down Expand Up @@ -2376,7 +2360,7 @@ interactions:
proto: HTTP/2.0
proto_major: 2
proto_minor: 0
content_length: 9578
content_length: 9659
body: |
{
"results": [
Expand Down Expand Up @@ -3177,12 +3161,19 @@ interactions:
}
]
},
{}
{
"vulns": [
{
"id": "UBUNTU-CVE-2025-14847",
"modified": "2025-12-26T08:25:05.686502Z"
}
]
}
]
}
headers:
Content-Length:
- "9578"
- "9659"
Content-Type:
- application/json
status: 200 OK
Expand Down Expand Up @@ -3918,7 +3909,7 @@ interactions:
proto: HTTP/2.0
proto_major: 2
proto_minor: 0
content_length: 9578
content_length: 9659
body: |
{
"results": [
Expand Down Expand Up @@ -4719,12 +4710,19 @@ interactions:
}
]
},
{}
{
"vulns": [
{
"id": "UBUNTU-CVE-2025-14847",
"modified": "2025-12-26T08:25:05.686502Z"
}
]
}
]
}
headers:
Content-Length:
- "9578"
- "9659"
Content-Type:
- application/json
status: 200 OK
Expand Down Expand Up @@ -5474,7 +5472,7 @@ interactions:
proto: HTTP/2.0
proto_major: 2
proto_minor: 0
content_length: 14084
content_length: 14165
body: |
{
"results": [
Expand Down Expand Up @@ -6584,12 +6582,19 @@ interactions:
}
]
},
{}
{
"vulns": [
{
"id": "UBUNTU-CVE-2025-14847",
"modified": "2025-12-26T08:25:05.686502Z"
}
]
}
]
}
headers:
Content-Length:
- "14084"
- "14165"
Content-Type:
- application/json
status: 200 OK
Expand Down Expand Up @@ -10959,7 +10964,7 @@ interactions:
},
{
"id": "GHSA-pq67-6m6q-mj2v",
"modified": "2025-06-19T16:15:11.736637Z"
"modified": "2025-12-22T21:47:12.568920Z"
},
{
"id": "GHSA-v845-jxx5-vc9f",
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -1286,7 +1286,7 @@ interactions:
},
{
"id": "GHSA-pq67-6m6q-mj2v",
"modified": "2025-06-19T16:15:11.736637Z"
"modified": "2025-12-22T21:47:12.568920Z"
},
{
"id": "GHSA-v845-jxx5-vc9f",
Expand Down Expand Up @@ -3601,7 +3601,7 @@ interactions:
proto: HTTP/2.0
proto_major: 2
proto_minor: 0
content_length: 9578
content_length: 9659
body: |
{
"results": [
Expand Down Expand Up @@ -4402,12 +4402,19 @@ interactions:
}
]
},
{}
{
"vulns": [
{
"id": "UBUNTU-CVE-2025-14847",
"modified": "2025-12-26T08:25:05.686502Z"
}
]
}
]
}
headers:
Content-Length:
- "9578"
- "9659"
Content-Type:
- application/json
status: 200 OK
Expand Down Expand Up @@ -5157,7 +5164,7 @@ interactions:
proto: HTTP/2.0
proto_major: 2
proto_minor: 0
content_length: 14084
content_length: 14165
body: |
{
"results": [
Expand Down Expand Up @@ -6267,12 +6274,19 @@ interactions:
}
]
},
{}
{
"vulns": [
{
"id": "UBUNTU-CVE-2025-14847",
"modified": "2025-12-26T08:25:05.686502Z"
}
]
}
]
}
headers:
Content-Length:
- "14084"
- "14165"
Content-Type:
- application/json
status: 200 OK
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -82,3 +82,8 @@ ignore = true
name = "util-linux"
reason = "Just want to test only unimportant vulns"
ignore = true

[[PackageOverrides]]
name = "zlib"
reason = "Just want to test only unimportant vulns"
ignore = true
Original file line number Diff line number Diff line change
Expand Up @@ -1951,7 +1951,7 @@ interactions:
},
{
"id": "GHSA-pq67-6m6q-mj2v",
"modified": "2025-06-19T16:15:11.736637Z"
"modified": "2025-12-22T21:47:12.568920Z"
},
{
"id": "GHSA-v845-jxx5-vc9f",
Expand Down
Loading
Loading