google / google/osv-scanner

scan source -r does not detect osv-scanner.json

Open
#1,938 2 comments 0 reactions 0 assignees View on GitHub
backlog enhancement
Dominant language
Go
Stars
11k
Forks
792
Avg merge
1d 20h
Merged PRs (30d)
48

Description

`osv-scanner scan source -r .` detects lockfiles automatically but does not detect `osv-scanner.json` and so `-L` must be used to list all `osv-scanner.json` files in the tree. It would be nice if `osv-scanner.json` was also detected as a lockfile.

It is possible that this is an X-Y problem - I generate `osv-scanner.json` in two cases:
- C/C++ git commit dependencies (I don't use git submodules, but my own script to clone into cache folder, I didn't find another way to pass commit IDs with SBOMs that OSV-Scanner would recognize)
- old chunks of code with a license (I use a fake package name with code description and a fake commit to attach a license via override in `osv-scanner.toml` to take advantage of OSV-Scanner license violation feature)

I wouldn't need `osv-scanner.json` if there was a better way to solve these two cases. Also the second case would be already improved if I could set commit `"0"` instead of some fake SHA256 which would be ignored and not really sent to osv.dev.

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.