Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Encode upstream qualifier on OS package pURLs #769

Merged
merged 1 commit into from Jan 25, 2022

Conversation

wagoodman
Copy link
Contributor

@wagoodman wagoodman commented Jan 24, 2022

This adds an additional upstream qualifier to the pURLs that we generate for OS-related packages to indicate source package information.

The pURL spec does not strictly support this qualifier, however, it does seem like the best current option for encoding source-package information for a package.

Related to anchore/grype#395

cc: @kzantow

Signed-off-by: Alex Goodman <alex.goodman@anchore.com>
@wagoodman wagoodman added the enhancement New feature or request label Jan 24, 2022
@wagoodman wagoodman requested a review from a team January 24, 2022 23:17
@wagoodman wagoodman self-assigned this Jan 24, 2022
@github-actions
Copy link

Benchmark Test Results

Benchmark results from the latest changes vs base branch
name                                                       old time/op    new time/op    delta
ImagePackageCatalogers/ruby-gemspec-cataloger-2              1.77ms ± 8%    1.65ms ± 7%    ~     (p=0.056 n=5+5)
ImagePackageCatalogers/python-package-cataloger-2            3.95ms ± 3%    3.65ms ± 1%  -7.74%  (p=0.008 n=5+5)
ImagePackageCatalogers/php-composer-installed-cataloger-2    1.36ms ± 2%    1.24ms ± 2%  -8.72%  (p=0.008 n=5+5)
ImagePackageCatalogers/javascript-package-cataloger-2        1.07ms ± 5%    1.04ms ± 7%    ~     (p=0.310 n=5+5)
ImagePackageCatalogers/dpkgdb-cataloger-2                    1.23ms ± 3%    1.24ms ± 1%    ~     (p=0.310 n=5+5)
ImagePackageCatalogers/rpmdb-cataloger-2                     1.09ms ± 3%    1.11ms ± 0%    ~     (p=0.190 n=5+4)
ImagePackageCatalogers/java-cataloger-2                      17.4ms ± 2%    16.6ms ± 3%  -4.29%  (p=0.008 n=5+5)
ImagePackageCatalogers/apkdb-cataloger-2                     1.63ms ± 6%    1.60ms ± 5%    ~     (p=0.548 n=5+5)
ImagePackageCatalogers/go-module-binary-cataloger-2          2.35µs ± 1%    2.23µs ± 6%    ~     (p=0.095 n=5+5)

name                                                       old alloc/op   new alloc/op   delta
ImagePackageCatalogers/ruby-gemspec-cataloger-2               253kB ± 0%     253kB ± 0%  +0.20%  (p=0.008 n=5+5)
ImagePackageCatalogers/python-package-cataloger-2            1.06MB ± 0%    1.07MB ± 0%    ~     (p=0.095 n=5+5)
ImagePackageCatalogers/php-composer-installed-cataloger-2     253kB ± 0%     254kB ± 0%    ~     (p=0.222 n=5+5)
ImagePackageCatalogers/javascript-package-cataloger-2         208kB ± 0%     208kB ± 0%  +0.14%  (p=0.032 n=5+5)
ImagePackageCatalogers/dpkgdb-cataloger-2                     254kB ± 0%     255kB ± 0%  +0.17%  (p=0.008 n=5+5)
ImagePackageCatalogers/rpmdb-cataloger-2                      236kB ± 0%     236kB ± 0%  +0.11%  (p=0.016 n=5+5)
ImagePackageCatalogers/java-cataloger-2                      3.78MB ± 0%    3.78MB ± 0%    ~     (p=0.690 n=5+5)
ImagePackageCatalogers/apkdb-cataloger-2                     1.30MB ± 0%    1.30MB ± 0%  +0.10%  (p=0.032 n=5+5)
ImagePackageCatalogers/go-module-binary-cataloger-2            560B ± 0%      560B ± 0%    ~     (all equal)

name                                                       old allocs/op  new allocs/op  delta
ImagePackageCatalogers/ruby-gemspec-cataloger-2               6.33k ± 0%     6.33k ± 0%    ~     (p=1.000 n=5+5)
ImagePackageCatalogers/python-package-cataloger-2             21.4k ± 0%     21.4k ± 0%    ~     (p=1.000 n=5+5)
ImagePackageCatalogers/php-composer-installed-cataloger-2     7.26k ± 0%     7.26k ± 0%    ~     (p=1.000 n=5+5)
ImagePackageCatalogers/javascript-package-cataloger-2         5.34k ± 0%     5.34k ± 0%    ~     (all equal)
ImagePackageCatalogers/dpkgdb-cataloger-2                     7.10k ± 0%     7.11k ± 0%  +0.08%  (p=0.008 n=5+5)
ImagePackageCatalogers/rpmdb-cataloger-2                      6.82k ± 0%     6.83k ± 0%  +0.09%  (p=0.008 n=5+5)
ImagePackageCatalogers/java-cataloger-2                       74.7k ± 0%     74.7k ± 0%  -0.02%  (p=0.016 n=5+5)
ImagePackageCatalogers/apkdb-cataloger-2                      7.36k ± 0%     7.38k ± 0%  +0.17%  (p=0.016 n=4+5)
ImagePackageCatalogers/go-module-binary-cataloger-2            13.0 ± 0%      13.0 ± 0%    ~     (all equal)

@wagoodman wagoodman enabled auto-merge (squash) January 25, 2022 14:31
@wagoodman wagoodman merged commit 6f0fad7 into main Jan 25, 2022
@wagoodman wagoodman deleted the purl-encode-upstream-pkg branch January 25, 2022 14:55
jonasagx pushed a commit to jonasagx/syft that referenced this pull request Jan 28, 2022
Signed-off-by: Alex Goodman <alex.goodman@anchore.com>
GijsCalis pushed a commit to GijsCalis/syft that referenced this pull request Feb 19, 2024
Signed-off-by: Alex Goodman <alex.goodman@anchore.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New feature or request
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

2 participants