diff --git a/pkgs/tools/security/osv-scanner/default.nix b/pkgs/tools/security/osv-scanner/default.nix new file mode 100644 index 000000000000..192d9f13b0ff --- /dev/null +++ b/pkgs/tools/security/osv-scanner/default.nix @@ -0,0 +1,42 @@ +{ lib +, buildGoModule +, fetchFromGitHub +, testers +, osv-scanner +}: +buildGoModule rec { + pname = "osv-scanner"; + version = "1.0.2"; + + src = fetchFromGitHub { + owner = "google"; + repo = pname; + rev = "v${version}"; + hash = "sha256-RmR6ZJg+UkE+eSmz4hGuMlObl6UvnGKNoLtBGVKoQ8Q="; + }; + + vendorHash = "sha256-HUgzoQuWBRnt8+lCiu9QfO1XR5EMnqVIkrL+nIMf0IA="; + + ldflags = [ + "-s" + "-w" + "-X main.version=${version}" + "-X main.commit=n/a" + "-X main.date=1970-01-01T00:00:00Z" + ]; + + # Tests require network connectivity to query https://api.osv.dev. + doCheck = false; + + passthru.tests.version = testers.testVersion { + package = osv-scanner; + }; + + meta = with lib; { + description = "Vulnerability scanner written in Go which uses the data provided by https://osv.dev"; + homepage = "https://github.com/google/osv-scanner"; + changelog = "https://github.com/google/osv-scanner/releases/tag/v${version}"; + license = licenses.asl20; + maintainers = with maintainers; [ stehessel urandom ]; + }; +} diff --git a/pkgs/top-level/all-packages.nix b/pkgs/top-level/all-packages.nix index 6f670f1535b5..b81d61fd6f6b 100644 --- a/pkgs/top-level/all-packages.nix +++ b/pkgs/top-level/all-packages.nix @@ -5191,6 +5191,8 @@ with pkgs; osv-detector = callPackage ../tools/security/osv-detector {}; + osv-scanner = callPackage ../tools/security/osv-scanner {}; + pastel = callPackage ../applications/misc/pastel { inherit (darwin.apple_sdk.frameworks) Security; };