feat: include Debian source package in get_packages
dpkg-query now also reports ${source:Package} as source_package, so consumers
can match installed binaries to the correct Debian source (e.g. openssh-server
-> openssh) for accurate OSV vulnerability lookups.
This commit is contained in:
@@ -244,7 +244,8 @@ class ProxmoxSystemMixin:
|
||||
|
||||
# Installed packages via SSH dpkg-query
|
||||
raw = self._exec_ssh_command(
|
||||
"dpkg-query -W -f='${Package}\\t${Version}\\t${db:Status-Status}\\t${Installed-Size}\\n'"
|
||||
"dpkg-query -W -f="
|
||||
"'${Package}\\t${Version}\\t${db:Status-Status}\\t${Installed-Size}\\t${source:Package}\\n'"
|
||||
" 2>/dev/null"
|
||||
)
|
||||
result: list[_JsonDict] = []
|
||||
@@ -256,6 +257,9 @@ class ProxmoxSystemMixin:
|
||||
version = parts[1] if len(parts) > 1 else ""
|
||||
status = parts[2] if len(parts) > 2 else "installed"
|
||||
size_kb = parts[3] if len(parts) > 3 else "0"
|
||||
# Debian source package (differs from the binary for split packages,
|
||||
# e.g. openssh-server → openssh). Needed for accurate OSV matching.
|
||||
source_package = parts[4] if len(parts) > 4 and parts[4] else name
|
||||
if not name or status != "installed":
|
||||
continue
|
||||
size_bytes = int(size_kb) * 1024 if size_kb.isdigit() else 0
|
||||
@@ -266,6 +270,7 @@ class ProxmoxSystemMixin:
|
||||
"description": "",
|
||||
"size": size_bytes,
|
||||
"source": "pve",
|
||||
"source_package": source_package,
|
||||
"upgrade_version": upgradable.get(name, ""),
|
||||
})
|
||||
return result
|
||||
|
||||
Reference in New Issue
Block a user