melange
melange copied to clipboard
Only consider files in expected path (not under) for cmd provides.
Anything with +x in usr/bin/.../node_modules/... was getting marked as a command provided by the apk.
Instead, of considering any path under usr/bin, only consider usr/bin/.
Melange Pull Request Template
Functional Changes
- [ ] This change can build all of Wolfi without errors (describe results in notes)
Notes:
SCA Changes
- [ ] Examining several representative APKs show no regression / the desired effect (details in notes)
Notes:
Linter
- [ ] The new check is clean across Wolfi
- [ ] The new check is opt-in or a warning
Notes:
closing this, i guess i oepned it twice. prefer https://github.com/chainguard-dev/melange/pull/1164/files