anchore / anchore/syft

Publish official linux syft (and friends) in a repo

Open
#3,261 0 comments 0 reactions 0 assignees View on GitHub
enhancement release
Dominant language
Go
Stars
9.6k
Forks
954
Avg merge
23h 27m
Merged PRs (30d)
48

Description

Syft, Grype and Grant have rpm and deb packages in the GitHub releases page, which is great.

However, that means users of those packages don't automatically get updates, as they might from a repo.

We should consider pushing all our debs and rpms to our own hosted repository so users can get updates without having to hunt them down from our releases page.

One option could be to publish to S3 using a tool like https://github.com/deb-s3/deb-s3

While we could work with Debian, Canonical, RedHat, Rocky or Alma, that would likely result over time in outdated releases of our software in stable releases, due to their publishing policies.

Contributor guide

Open the contributing guide

Research direction

The issue names no repository files, tests, or release entry points. Start by reviewing how GitHub releases produce the Syft, Grype, and Grant deb and rpm packages, then evaluate the proposed deb-s3 and S3 approach. Done would require a decided repository design and an agreed publishing and update workflow for all three tools.

Written by the indexing model from the issue text.

Assessment

Tech stack
go
Domain
release
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.