Conversation
Signed-off-by: Yuvraj Saxena <ysaxenax@gmail.com>
0xXA
added a commit
to 0xXA/osv-scalibr
that referenced
this pull request
Sep 17, 2026
…ted extractor plugin for Haskell cabal.project.freeze files The `haskell/cabal` extractor previously parsed `cabal.project.freeze` files. This change overhauls the plugin completely to instead extract packages from cabal's installed-package database (`.conf` files under `<cabal-store>/.../package.db/`), parsing the name, version, and depends fields (including multiline depends: blocks) to report both the package itself and its direct dependencies. Parsing these `.conf` files is meaningfully more complicated than the old cabal.project.freeze parsing: cabal.project.freeze was a flat list of `any.<pkg> ==<version>` constraints matched with a single regex, whereas the `.conf` format is a field-based, indentation-layout (top-level name:/version:/depends: fields, with depends: able to continue across multiple indented lines) that has to be scanned statefully line-by-line to correctly separate the package's own identity from its dependency list. The original `cabal.project.freeze` parsing logic is moved out into a new `haskell/cabalprojectfreeze` extractor package, preserving the old behavior and test data under its own plugin name (`haskell/cabalprojectfreeze`). Closes Issue: google#2147 Testbed PR: google/security-testbeds#259 Signed-off-by: Yuvraj Saxena <ysaxenax@gmail.com>
0xXA
added a commit
to 0xXA/osv-scalibr
that referenced
this pull request
Sep 17, 2026
…ted extractor plugin for Haskell cabal.project.freeze files The `haskell/cabal` extractor previously parsed `cabal.project.freeze` files. This change overhauls the plugin completely to instead extract packages from cabal's installed-package database (`.conf` files under `<cabal-store>/.../package.db/`), parsing the name, version, and depends fields (including multiline depends: blocks) to report both the package itself and its direct dependencies. Parsing these `.conf` files is meaningfully more complicated than the old cabal.project.freeze parsing: cabal.project.freeze was a flat list of `any.<pkg> ==<version>` constraints matched with a single regex, whereas the `.conf` format is a field-based, indentation-layout (top-level name:/version:/depends: fields, with depends: able to continue across multiple indented lines) that has to be scanned statefully line-by-line to correctly separate the package's own identity from its dependency list. The original `cabal.project.freeze` parsing logic is moved out into a new `haskell/cabalprojectfreeze` extractor package, preserving the old behavior and test data under its own plugin name (`haskell/cabalprojectfreeze`). Closes Issue: google#2147 Testbed PR: google/security-testbeds#259 Signed-off-by: Yuvraj Saxena <ysaxenax@gmail.com>
0xXA
added a commit
to 0xXA/osv-scalibr
that referenced
this pull request
Sep 24, 2026
…ted extractor plugin for Haskell cabal.project.freeze files The `haskell/cabal` extractor previously parsed `cabal.project.freeze` files. This change overhauls the plugin completely to instead extract packages from cabal's installed-package database (`.conf` files under `<cabal-store>/.../package.db/`), parsing the name and version to report the package itself. Parsing these `.conf` files is meaningfully more complicated than the old cabal.project.freeze parsing: cabal.project.freeze was a flat list of `any.<pkg> ==<version>` constraints matched with a single regex, whereas the `.conf` format is a field-based, indentation-layout (top-level name:/version: fields) that has to be scanned statefully line-by-line. The original `cabal.project.freeze` parsing logic is moved out into a new `haskell/cabalprojectfreeze` extractor package, preserving the old behavior and test data under its own plugin name (`haskell/cabalprojectfreeze`). Closes Issue: google#2147 Testbed PR: google/security-testbeds#259 Signed-off-by: Yuvraj Saxena <ysaxenax@gmail.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
No description provided.