Publish official linux syft (and friends) in a repo
- Dominant language
- Go
- Stars
- 9.6k
- Forks
- 954
- Avg merge
- 23h 27m
- Merged PRs (30d)
- 48
Description
Syft, Grype and Grant have rpm and deb packages in the GitHub releases page, which is great.
However, that means users of those packages don't automatically get updates, as they might from a repo.
We should consider pushing all our debs and rpms to our own hosted repository so users can get updates without having to hunt them down from our releases page.
One option could be to publish to S3 using a tool like https://github.com/deb-s3/deb-s3
While we could work with Debian, Canonical, RedHat, Rocky or Alma, that would likely result over time in outdated releases of our software in stable releases, due to their publishing policies.
Contributor guide
Research direction
The issue names no repository files, tests, or release entry points. Start by reviewing how GitHub releases produce the Syft, Grype, and Grant deb and rpm packages, then evaluate the proposed deb-s3 and S3 approach. Done would require a decided repository design and an agreed publishing and update workflow for all three tools.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- go
- Domain
- release
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 25/100