feat: include Debian source package in get_packages

dpkg-query now also reports ${source:Package} as source_package, so consumers
can match installed binaries to the correct Debian source (e.g. openssh-server
-> openssh) for accurate OSV vulnerability lookups.
This commit is contained in:
Christian Manivong
2026-08-23 17:45:07 +07:00
parent 20fcf2ebc3
commit c97c282648
+6 -1
View File
@@ -244,7 +244,8 @@ class ProxmoxSystemMixin:
# Installed packages via SSH dpkg-query # Installed packages via SSH dpkg-query
raw = self._exec_ssh_command( raw = self._exec_ssh_command(
"dpkg-query -W -f='${Package}\\t${Version}\\t${db:Status-Status}\\t${Installed-Size}\\n'" "dpkg-query -W -f="
"'${Package}\\t${Version}\\t${db:Status-Status}\\t${Installed-Size}\\t${source:Package}\\n'"
" 2>/dev/null" " 2>/dev/null"
) )
result: list[_JsonDict] = [] result: list[_JsonDict] = []
@@ -256,6 +257,9 @@ class ProxmoxSystemMixin:
version = parts[1] if len(parts) > 1 else "" version = parts[1] if len(parts) > 1 else ""
status = parts[2] if len(parts) > 2 else "installed" status = parts[2] if len(parts) > 2 else "installed"
size_kb = parts[3] if len(parts) > 3 else "0" size_kb = parts[3] if len(parts) > 3 else "0"
# Debian source package (differs from the binary for split packages,
# e.g. openssh-server → openssh). Needed for accurate OSV matching.
source_package = parts[4] if len(parts) > 4 and parts[4] else name
if not name or status != "installed": if not name or status != "installed":
continue continue
size_bytes = int(size_kb) * 1024 if size_kb.isdigit() else 0 size_bytes = int(size_kb) * 1024 if size_kb.isdigit() else 0
@@ -266,6 +270,7 @@ class ProxmoxSystemMixin:
"description": "", "description": "",
"size": size_bytes, "size": size_bytes,
"source": "pve", "source": "pve",
"source_package": source_package,
"upgrade_version": upgradable.get(name, ""), "upgrade_version": upgradable.get(name, ""),
}) })
return result return result