Re: modifying pkg-audit to ignore specified vulns
"Dan Langille" <[email protected]>
| Newsgroups | gmane.os.freebsd.devel.ports |
|---|---|
| Message-ID | <[email protected]> |
On Mon, Aug 10, 2026, at 5:15 PM, Dan Mahoney (Ports) wrote: > Dan, > > This feels worthwhile. We also run a daily pkg-audit on our whole > fleet at the dayjob. > > I think this is something that should be possible to continue to use > the existing functionality in pkg, but add an additional knob to the > shipped periodic-script to specify a post-process filter that you'd > specify in periodic.conf, that way you don't add any additional > dependencies to pkg itself, if you want to add in an xmlparser or just > a simple grep script, or whatnot. > > If that feels reasonable to you, and you think bapt would be interested > in picking up the fairly simple change to the periodic script, this is > probably the most base-compatible way to do everything? A solution which is simple (and optional for the user) is likely to be accepted. > On the actual filter, ideally you'd want to filter based on either port > name, or a specific vuln-id (either the CVE number or the FreeBSD XML > entry). This is a few lines of perl but possibly also sed or awk. I will use the names contained within /var/db/pkg/vuln.xml: For me, I'm happy to start filtering by `vid`. If it's just as easy to filter by `cvename great`. pkg-audit supplies both values. > > -Dan > >> On Aug 10, 2026, at 1:27 PM, Dan Langille <[email protected]> wrote: >> >> Hello, >> >> I use periodic/security/410.pkg-audit as part of a Nagios reporting tool. This monitoring check lets me know when a particular host has a vuln. I have used it, or something like it, for years. >> >> Alert fatigue is a real issue. Sometimes it takes months for given known vuln to be fixed. In the meantime, a sea of red covers the Nagios page making it difficult to see new / other vulns. >> >> My goal: selectively silence a vuln. >> >> Background: Back in April, I posted about this issue on Mastodon. One solution, for ignoring vulns on a given port, worked. https://bsd.network/web/@[email protected]/115925654143396302 >> >> However, now I want to modify this approach and ignore a list of vulns. >> >> In short, alter 410.pkg-audit to use a user-specified file and to ignore upon any vulns specified in that file. >> >> My short idea: >> >> 1 - use the --file option on pkg-audit >> 2 - using /var/db/pkg/vuln.xml as input, remove the vuln you don't want to see >> 3 - output the results to a new file, say: /var/db/pkg/vuln-filtered.xml >> 4 - run pkg-audit -f /var/db/pkg/vuln-filtered.xml >> >> For step 2, the file is XML and I'm sure there are many tools to choose from which will delete based on vid in this: >> >> 6d3488ae-2e0f-11f1-88c7-00a098b42aeb >> 0be929a5-2e0f-11f1-88c7-00a098b42aeb >> >> I'm posting in the hopes that someone takes up this challenge and codes something up. I'm happy to test, but can't do the coding. >> >> -- >> Dan Langille >> [email protected] -- Dan Langille [email protected]