fix(ecosystems): lineage-aware version comparison for Docker Hardened Images - #5716
Open
aubm wants to merge 4 commits into
Open
fix(ecosystems): lineage-aware version comparison for Docker Hardened Images#5716aubm wants to merge 4 commits into
aubm wants to merge 4 commits into
Conversation
|
Thanks for your pull request! It looks like this may be your first contribution to a Google open source project. Before we can look at your pull request, you'll need to sign a Contributor License Agreement (CLA). View this failed invocation of the CLA check for more information. For the most up to date status, view the checks section at the bottom of the pull request. |
aubm
force-pushed
the
dhi-ecosystem-version-comparator
branch
from
July 27, 2026 17:28
e4b919a to
c44a973
Compare
6 tasks
…ened Images Docker Hardened Images was registered as a SemverEcosystem, but DHI OS packages are repackaged Alpine (apk) and Debian (dpkg) packages that keep their upstream version syntax (e.g. "8.4.0-r0", "7.88.1-10+deb13u2"). Semver comparison mis-orders these -- it compares the apk "-rN" release lexically (so r10 < r2) and does not understand Debian epochs/revisions. Add a DHIEcosystem helper that delegates version handling to the lineage ecosystem named in the "<lineage>:<release>" suffix (Alpine/APK for "...:Alpine:<rel>", Debian for "...:Debian:<rel>"), mirroring the TuxCareEcosystem wrap-an-inner pattern.
aubm
force-pushed
the
dhi-ecosystem-version-comparator
branch
from
July 27, 2026 19:09
c44a973 to
68ab228
Compare
Contributor
Per review feedback on google#5716, the ecosystem logic has migrated to Go, so this implements Docker Hardened Images version comparison in go/osv/ecosystem and removes the earlier Python implementation. Register DHI with a lineage-aware factory that delegates version handling to the ecosystem named in the :Alpine:/:Debian: suffix (apk / dpkg), mirroring tuxcareFactory. IsSemver is false: DHI uses ECOSYSTEM ranges and apk/dpkg version ordering, not SemVer.
Author
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Docker Hardened Imageswas registered as aSemverEcosystem, but DHI OS packages are repackaged Alpine (apk) and Debian (dpkg) packages that keep their upstream version syntax (e.g.8.4.0-r0,7.88.1-10+deb13u2). Semver comparison mis-orders these — it compares the apk-rNrelease lexically (sor10sorts beforer2) and does not understand Debian epochs/revisions.This adds a
DHIEcosystemhelper that delegates version handling to the lineage ecosystem named in the<lineage>:<release>suffix — Alpine/APK for…:Alpine:<rel>, Debian for…:Debian:<rel>— mirroring the existingTuxCareEcosystemwrap-an-inner pattern. As a resultDocker Hardened Imagesis no longer reported as semver.Tests added in
osv/ecosystems/_ecosystems_test.py. Relates to #4388.🤖 Generated with Claude Code