grype: 0.87.0 -> 0.91.2 (#402745)

This commit is contained in:
Fabian Affolter
2025-04-30 00:54:59 +02:00
committed by GitHub
2 changed files with 15 additions and 17 deletions
+15 -13
View File
@@ -7,15 +7,15 @@
openssl,
}:
buildGoModule rec {
buildGoModule (finalAttrs: {
pname = "grype";
version = "0.87.0";
version = "0.91.2";
src = fetchFromGitHub {
owner = "anchore";
repo = "grype";
tag = "v${version}";
hash = "sha256-El7cegeHMb6fhO1Vr6FK0E3Mlk/dbU0Dv4lUYNu0Gcc=";
tag = "v${finalAttrs.version}";
hash = "sha256-y1uq7tNTzAhEAX/LZkrwfAanWDJpzuM+AWHlVcOVpqg=";
# populate values that require us to use git. By doing this in postFetch we
# can delete .git afterwards and maintain better reproducibility of the src.
leaveDotGit = true;
@@ -30,7 +30,7 @@ buildGoModule rec {
proxyVendor = true;
vendorHash = "sha256-SbKvDAzWq58O0e/+1r5oI3rxfdsnPenMPwqNRTOe7AI=";
vendorHash = "sha256-A0YvbCI2n67Q9vA86PMY3DUGi6zbTgR8iWg8Nfvy9IQ=";
nativeBuildInputs = [ installShellFiles ];
@@ -46,8 +46,8 @@ buildGoModule rec {
ldflags = [
"-s"
"-w"
"-X=main.version=${version}"
"-X=main.gitDescription=v${version}"
"-X=main.version=${finalAttrs.version}"
"-X=main.gitDescription=v${finalAttrs.version}"
"-X=main.gitTreeState=clean"
];
@@ -67,13 +67,15 @@ buildGoModule rec {
unset ldflags
# patch utility script
patchShebangs grype/db/legacy/distribution/test-fixtures/tls/generate-x509-cert-pair.sh
patchShebangs grype/db/v5/distribution/test-fixtures/tls/generate-x509-cert-pair.sh
# FIXME: these tests fail when building with Nix
substituteInPlace test/cli/config_test.go \
--replace-fail "Test_configLoading" "Skip_configLoading"
substituteInPlace test/cli/db_providers_test.go \
--replace-fail "TestDBProviders" "SkipDBProviders"
substituteInPlace grype/presenter/cyclonedx/presenter_test.go \
--replace-fail "TestCycloneDxPresenterDir" "SkipCycloneDxPresenterDir"
# remove tests that depend on docker
substituteInPlace test/cli/cmd_test.go \
@@ -115,20 +117,20 @@ buildGoModule rec {
--zsh <($out/bin/grype completion zsh)
'';
meta = with lib; {
meta = {
description = "Vulnerability scanner for container images and filesystems";
homepage = "https://github.com/anchore/grype";
changelog = "https://github.com/anchore/grype/releases/tag/v${version}";
changelog = "https://github.com/anchore/grype/releases/tag/v${finalAttrs.version}";
longDescription = ''
As a vulnerability scanner grype is able to scan the contents of a
container image or filesystem to find known vulnerabilities.
'';
license = with licenses; [ asl20 ];
maintainers = with maintainers; [
license = with lib.licenses; [ asl20 ];
maintainers = with lib.maintainers; [
fab
jk
kashw2
];
mainProgram = "grype";
};
}
})
-4
View File
@@ -2447,10 +2447,6 @@ with pkgs;
pythonPackages = python3Packages;
};
grype = callPackage ../by-name/gr/grype/package.nix {
buildGoModule = buildGo123Module;
};
hocr-tools = with python3Packages; toPythonApplication hocr-tools;
hopper = qt5.callPackage ../development/tools/analysis/hopper { };