advisory-scan: --image takes NAME=FROM:TO
Restores the single-value form (operator preference) under the --image name. Repeat the flag per image, all in one call. Malformed values warn on stderr and are skipped rather than aborting the scan, since it is an additive pre-step. Counts unchanged: discourse 128 with redis / 123 without, gitea 2.
This commit is contained in:
@@ -353,8 +353,8 @@ def scan(recipe: str, v_from: str | None, v_to: str | None, registry_dir: str,
|
||||
# is classified against ITS OWN window, and the count is the union across windows.
|
||||
#
|
||||
# --from/--to → the PRIMARY app repo (first github source in the registry)
|
||||
# --image NAME FROM TO → any other source whose name contains NAME (repeatable),
|
||||
# e.g. --image redis 7.4 8.10
|
||||
# --image NAME=FROM:TO → any other source whose name contains NAME (repeatable),
|
||||
# e.g. --image redis=7.4:8.10
|
||||
#
|
||||
# A source with no window is not classified: its advisories are listed as unclassified so they
|
||||
# stay visible without inflating the count.
|
||||
@@ -506,14 +506,21 @@ def main() -> int:
|
||||
ap.add_argument("--to", dest="v_to", default=None)
|
||||
ap.add_argument("--json", action="store_true", help="emit raw JSON instead of markdown")
|
||||
ap.add_argument("--registry", default=REGISTRY_DIR)
|
||||
ap.add_argument("--image", action="append", default=[], nargs=3,
|
||||
metavar=("NAME", "FROM", "TO"),
|
||||
ap.add_argument("--image", action="append", default=[], metavar="NAME=FROM:TO",
|
||||
help="a sidecar image and the versions it moved between, e.g. "
|
||||
"--image redis 7.4 8.10 (repeatable). NAME matches a source repo name; "
|
||||
"--image redis=7.4:8.10 (repeatable). NAME matches a source repo name; "
|
||||
"its advisories are then counted against ITS OWN versions instead of "
|
||||
"being left unclassified.")
|
||||
a = ap.parse_args()
|
||||
rep = scan(a.recipe, a.v_from, a.v_to, a.registry, [tuple(x) for x in a.image])
|
||||
images = []
|
||||
for spec in a.image:
|
||||
name, _, rng = spec.partition('=')
|
||||
vf, _, vt = rng.partition(':')
|
||||
if name and vf and vt:
|
||||
images.append((name, vf, vt))
|
||||
else:
|
||||
print(f'ignoring malformed --image {spec!r} (expected NAME=FROM:TO)', file=sys.stderr)
|
||||
rep = scan(a.recipe, a.v_from, a.v_to, a.registry, images)
|
||||
print(json.dumps(rep, indent=2) if a.json else markdown(rep))
|
||||
return 0
|
||||
|
||||
|
||||
Reference in New Issue
Block a user