google / google/osv-scanner

Next major (v3)

Open
#2,582 0 comments 0 reactions 1 assignee Claimed by @another-rex View on GitHub
backlog v3
Dominant language
Go
Stars
11k
Forks
792
Avg merge
1d 20h
Merged PRs (30d)
48

Description

This is a list of things we're considering doing for the next major, though not everything listed will necessarily be done in this major:

- [ ] Remove deprecated flags
- [ ] `--sbom` (#2452)
- [ ] `--output`
- [ ] `--gh-annotations`
- [ ] Decide what experimental flags / actions to promote
- [ ] plugins (`--plugins`, `--disable-plugins`, `--no-default-plugins`
- [ ] http client
- [ ] deprecated packages (`--flag-deprecated-packages`)
- [ ] config updating (pending #2534)
- [ ] Remove interactive mode
- [ ] Remove deprecated GH workflows
- [ ] `osv-scanner-reusable-pr.yml`
- [ ] `osv-scanner-reusable.yml`
- [ ] Review names of public types and functions
- [ ] Rename `models.VulnerabilityFlattened`
- [ ] Rename `models.PackageVulns`
- [ ] Use or remove `ErrAPIFailed`
- [ ] Add context to `osvscanner.makeVulnRequestWithMatcher` (and maybe `osvscanner.Scan`?)
- [ ] Move `ScanResults.ScanParameters` field
- [ ] Change JSON output
- [ ] Disable unsafe plugins by default (https://github.com/google/osv-scanner/issues/2633)

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.