Skip to content

Add testbed for Haskell Cabal OSV-Scalibr Extractor Plugin - #259

Open
0xXA wants to merge 1 commit into
google:mainfrom
0xXA:cabal
Open

0xXA wants to merge 1 commit into
google:mainfrom
0xXA:cabal

Conversation

@0xXA

@0xXA 0xXA commented Sep 17, 2026

Copy link
Copy Markdown

No description provided.

Signed-off-by: Yuvraj Saxena <ysaxenax@gmail.com>
0xXA added a commit to 0xXA/osv-scalibr that referenced this pull request Sep 17, 2026
…ted extractor plugin for Haskell cabal.project.freeze files

The `haskell/cabal` extractor previously parsed `cabal.project.freeze` files. This change overhauls the plugin completely to instead extract packages from cabal's installed-package database (`.conf` files under `<cabal-store>/.../package.db/`), parsing the name, version, and depends fields (including multiline depends: blocks) to report both the package itself and its direct dependencies.

Parsing these `.conf` files is meaningfully more complicated than the old cabal.project.freeze parsing: cabal.project.freeze was a flat list of `any.<pkg> ==<version>` constraints matched with a single regex, whereas the `.conf` format is a field-based, indentation-layout (top-level name:/version:/depends: fields, with depends: able to continue across multiple indented lines) that has to be scanned statefully line-by-line to correctly separate the package's own
identity from its dependency list.

The original `cabal.project.freeze` parsing logic is moved out into a new `haskell/cabalprojectfreeze` extractor package, preserving the old behavior and test data under its own plugin name (`haskell/cabalprojectfreeze`).

Closes Issue: google#2147
Testbed PR: google/security-testbeds#259

Signed-off-by: Yuvraj Saxena <ysaxenax@gmail.com>
0xXA added a commit to 0xXA/osv-scalibr that referenced this pull request Sep 17, 2026
…ted extractor plugin for Haskell cabal.project.freeze files

The `haskell/cabal` extractor previously parsed `cabal.project.freeze` files. This change overhauls the plugin completely to instead extract packages from cabal's installed-package database (`.conf` files under `<cabal-store>/.../package.db/`), parsing the name, version, and depends fields (including multiline depends: blocks) to report both the package itself and its direct dependencies.

Parsing these `.conf` files is meaningfully more complicated than the old cabal.project.freeze parsing: cabal.project.freeze was a flat list of `any.<pkg> ==<version>` constraints matched with a single regex, whereas the `.conf` format is a field-based, indentation-layout (top-level name:/version:/depends: fields, with depends: able to continue across multiple indented lines) that has to be scanned statefully line-by-line to correctly separate the package's own
identity from its dependency list.

The original `cabal.project.freeze` parsing logic is moved out into a new `haskell/cabalprojectfreeze` extractor package, preserving the old behavior and test data under its own plugin name (`haskell/cabalprojectfreeze`).

Closes Issue: google#2147
Testbed PR: google/security-testbeds#259

Signed-off-by: Yuvraj Saxena <ysaxenax@gmail.com>
0xXA added a commit to 0xXA/osv-scalibr that referenced this pull request Sep 24, 2026
…ted extractor plugin for Haskell cabal.project.freeze files

The `haskell/cabal` extractor previously parsed `cabal.project.freeze` files. This change overhauls the plugin completely to instead extract packages from cabal's installed-package database (`.conf` files under `<cabal-store>/.../package.db/`), parsing the name and version to report the package itself.

Parsing these `.conf` files is meaningfully more complicated than the old cabal.project.freeze parsing: cabal.project.freeze was a flat list of `any.<pkg> ==<version>` constraints matched with a single regex, whereas the `.conf` format is a field-based, indentation-layout (top-level name:/version: fields) that has to be scanned statefully line-by-line.

The original `cabal.project.freeze` parsing logic is moved out into a new `haskell/cabalprojectfreeze` extractor package, preserving the old behavior and test data under its own plugin name (`haskell/cabalprojectfreeze`).

Closes Issue: google#2147
Testbed PR: google/security-testbeds#259

Signed-off-by: Yuvraj Saxena <ysaxenax@gmail.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant