Skip to content

apk: add more qualifiers widely used by scanners and tools - #818

Open
xnox wants to merge 2 commits into
package-url:mainfrom
xnox:apk-qualifiers
Open

apk: add more qualifiers widely used by scanners and tools#818
xnox wants to merge 2 commits into
package-url:mainfrom
xnox:apk-qualifiers

Conversation

@xnox

@xnox xnox commented Feb 21, 2026

Copy link
Copy Markdown

Many apk tools are using additional qualifiers for apk
purl. Contribute the status quo as a specification.

Similar to many other purls, distro= is in use by syft/grype and many
other tools to provide a more specific distribution version for a
given namespace. This is useful to tell apart apk from different
alpine release branches.

Syft uses upstream= to denote the package origin, which is loosely a
source package name or "origin" in apk-tools native speak. The name is
unfortunate, but it is widely used. It helps to identify and match
PURLs with the vulnerability feeds - as universally vulnerability
feeds are not on per binary apk name, but on the "origin" name.

Many apk tools are using additional qualifiers for apk
purl. Contribute the status quo as a specification.

Similar to many other purls, distro= is in use by syft/grype and many
other tools to provide a more specific distribution version for a
given namespace. This is useful to tell apart apk from different
alpine release branches.

Syft uses upstream= to denote the package origin, which is loosely a
source package name or "origin" in apk-tools native speak. The name is
unfortunate, but it is widely used. It helps to identify and match
PURLs with the vulnerability feeds - as universally vulnerability
feeds are not on per binary apk name, but on the "origin" name.
@pombredanne

Copy link
Copy Markdown
Member

@xnox Thanks!... do you mind to add an issue to support the discussion on this PR? I'd like to make sure we get some input from alpine for instance.

darkrift added a commit to darkrift/supply-chain that referenced this pull request May 15, 2026
This adds the PURL parser adding all the remaining tests (parse and
roundtrip) and implementing the missing normalization and validation
checks from the currently "standard" type specs.

It also adds a strict validation to make sure that only the defined
qualifiers are allowed, it is disabled by default on the parser because
some [reference
implementation](https://cyclonedx.slack.com/archives/C01PZRT73K9/p1776087096074749?thread_ts=1776084835.516999&cid=C01PZRT73K9)
and [security tools](package-url/purl-spec#818)
already output PURL that are not spec compliant.

The builder also now have that same strict parameter, but is true by
default.

Fixes bazel-contrib#126 and bazel-contrib#145
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants