Skip to content

Commit

Permalink
Merge remote-tracking branch 'origin' into yaml-json-scanners
Browse files Browse the repository at this point in the history
  • Loading branch information
nikpivkin committed Aug 8, 2024
2 parents 210294a + 65d991c commit d661f91
Show file tree
Hide file tree
Showing 29 changed files with 1,079 additions and 674 deletions.
4 changes: 2 additions & 2 deletions docs/docs/coverage/language/python.md
Original file line number Diff line number Diff line change
Expand Up @@ -42,7 +42,7 @@ Trivy parses your files generated by package managers in filesystem/repository s
### pip

#### Dependency detection
Trivy only parses [version specifiers](https://packaging.python.org/en/latest/specifications/version-specifiers/#id4) with `==` comparison operator and without `.*`.
Trivy only parses [version specifiers](https://packaging.python.org/en/latest/specifications/version-specifiers/#id5) with `==` comparison operator and without `.*`.
To convert unsupported version specifiers - use the `pip freeze` command.

```bash
Expand Down Expand Up @@ -119,7 +119,7 @@ License detection is not supported for `Poetry`.

## Packaging
Trivy parses the manifest files of installed packages in container image scanning and so on.
See [here](https://packaging.python.org/en/latest/discussions/wheel-vs-egg/) for the detail.
See [here](https://packaging.python.org/en/latest/discussions/package-formats/) for the detail.

### Egg
Trivy looks for `*.egg-info`, `*.egg-info/PKG-INFO`, `*.egg` and `EGG-INFO/PKG-INFO` to identify Python packages.
Expand Down
Loading

0 comments on commit d661f91

Please sign in to comment.