Skip to content
Draft
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
17 changes: 17 additions & 0 deletions deployment/build-and-stage.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -453,6 +453,21 @@ steps:
args: ['push', '--all-tags', 'gcr.io/oss-vdb/nvd-cve-osv']
waitFor: ['build-nvd-cve-osv', 'cloud-build-queue']

# Build/push repository-specific GHSA conversion image
- name: 'gcr.io/cloud-builders/docker'
entrypoint: 'bash'
args: ['-c', 'docker pull gcr.io/oss-vdb/repository-ghsa-convert:latest || exit 0']
id: 'pull-repository-ghsa-convert'
waitFor: ['setup']
- name: gcr.io/cloud-builders/docker
args: ['build', '-t', 'gcr.io/oss-vdb/repository-ghsa-convert:latest', '-t', 'gcr.io/oss-vdb/repository-ghsa-convert:$COMMIT_SHA', '-f', 'cmd/converters/repository-ghsa/Dockerfile', '--cache-from', 'gcr.io/oss-vdb/repository-ghsa-convert:latest', '--pull', '.']
dir: 'vulnfeeds'
id: 'build-repository-ghsa-convert'
waitFor: ['pull-repository-ghsa-convert']
- name: gcr.io/cloud-builders/docker
args: ['push', '--all-tags', 'gcr.io/oss-vdb/repository-ghsa-convert']
waitFor: ['build-repository-ghsa-convert', 'cloud-build-queue']

# Build website frontend assets
- name: 'node:24.18'
entrypoint: 'bash'
Expand Down Expand Up @@ -543,6 +558,7 @@ steps:
generatesitemap=gcr.io/oss-vdb/generatesitemap:$COMMIT_SHA,\
gitter=gcr.io/oss-vdb/gitter:$COMMIT_SHA,\
vanir-signatures=gcr.io/oss-vdb/vanir-signatures:$COMMIT_SHA,\
repository-ghsa-convert=gcr.io/oss-vdb/repository-ghsa-convert:$COMMIT_SHA,\
cron=gcr.io/oss-vdb/cron:$COMMIT_SHA"
]
dir: deployment/clouddeploy/gke-workers
Expand Down Expand Up @@ -612,3 +628,4 @@ images:
- 'gcr.io/oss-vdb/generatesitemap:$COMMIT_SHA'
- 'gcr.io/oss-vdb/gitter:$COMMIT_SHA'
- 'gcr.io/oss-vdb/vanir-signatures:$COMMIT_SHA'
- 'gcr.io/oss-vdb/repository-ghsa-convert:$COMMIT_SHA'
Original file line number Diff line number Diff line change
Expand Up @@ -9,3 +9,4 @@ resources:
- debian-first-version.yaml
- nvd-cve-osv.yaml
- nvd-mirror.yaml
- repository-ghsa-convert.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,30 @@
apiVersion: batch/v1
kind: CronJob
metadata:
name: repository-ghsa-convert
labels:
cronLastSuccessfulTimeMins: "420"
spec:
timeZone: Australia/Sydney
schedule: "0 */6 * * *"
concurrencyPolicy: Forbid
jobTemplate:
spec:
activeDeadlineSeconds: 7200
template:
spec:
containers:
- name: repository-ghsa-convert
image: repository-ghsa-convert
imagePullPolicy: Always
resources:
requests:
cpu: "1"
memory: "2G"
limits:
cpu: "2"
memory: "4G"
env:
- name: GITTER_HOST
value: http://gitter-service:8888
restartPolicy: Never
Original file line number Diff line number Diff line change
Expand Up @@ -29,3 +29,4 @@ patches:
- path: custommetrics.yaml
- path: gitter.yaml
- path: vanir-signatures.yaml
- path: repository-ghsa-convert.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,20 @@
apiVersion: batch/v1
kind: CronJob
metadata:
name: repository-ghsa-convert
spec:
jobTemplate:
spec:
template:
spec:
containers:
- name: repository-ghsa-convert
env:
- name: GOOGLE_CLOUD_PROJECT
value: oss-vdb-test
- name: OUTPUT_BUCKET
value: osv-test-ghsa-repo-conversion
- name: REPOS_GCS_PATH
value: gs://oss-vdb-test-repos/monitored_repositories.json
- name: NUM_WORKERS
value: "8"
Original file line number Diff line number Diff line change
Expand Up @@ -26,4 +26,5 @@ patches:
- path: custommetrics.yaml
- path: gitter.yaml
- path: vanir-signatures.yaml
- path: repository-ghsa-convert.yaml

Original file line number Diff line number Diff line change
@@ -0,0 +1,20 @@
apiVersion: batch/v1
kind: CronJob
metadata:
name: repository-ghsa-convert
spec:
jobTemplate:
spec:
template:
spec:
containers:
- name: repository-ghsa-convert
env:
- name: GOOGLE_CLOUD_PROJECT
value: oss-vdb
- name: OUTPUT_BUCKET
value: osv-ghsa-repo-conversion
- name: REPOS_GCS_PATH
value: gs://oss-vdb-repos/monitored_repositories.json
- name: NUM_WORKERS
value: "16"
35 changes: 35 additions & 0 deletions vulnfeeds/cmd/converters/repository-ghsa/Dockerfile
Original file line number Diff line number Diff line change
@@ -0,0 +1,35 @@
# Copyright 2026 Google LLC
#
# Licensed under the Apache License, Version 2.0 (the "License");
# you may not use this file except in compliance with the License.
# You may obtain a copy of the License at
#
# http://www.apache.org/licenses/LICENSE-2.0
#
# Unless required by applicable law or agreed to in writing, software
# distributed under the License is distributed on an "AS IS" BASIS,
# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
# See the License for the specific language governing permissions and
# limitations under the License.

FROM golang:1.27.1-alpine@sha256:cf6fca6641884b8433441b2b0652976f975e1d0fdd26d177eaaf8596087f3125 AS go_build

RUN mkdir /src
WORKDIR /src

COPY ./go.mod /src/go.mod
COPY ./go.sum /src/go.sum
RUN go mod download && go mod verify

COPY ./ /src/
RUN CGO_ENABLED=0 go build -o repository-ghsa ./cmd/converters/repository-ghsa/

FROM gcr.io/google.com/cloudsdktool/google-cloud-cli:alpine@sha256:be40864452bd6d7be21632a1dc18adf03d423de0bf2595f4a287c22400c484bb
RUN apk --no-cache add ca-certificates git

WORKDIR /root/
COPY --from=go_build /src/repository-ghsa ./
COPY ./cmd/converters/repository-ghsa/run_repository_ghsa.sh ./
RUN chmod +x /root/run_repository_ghsa.sh

ENTRYPOINT ["/root/run_repository_ghsa.sh"]
Loading
Loading