dev-vcs/trufflehog
Finds and verifies leaked credentials across git history and many sources
-
trufflehog-3.97.9~amd64 ~arm64
View
Download
Browse License: AGPL-3 Apache-2.0 BSD BSD-2 CC0-1.0 ISC LGPL-3 MIT MPL-2.0 public-domain Overlay: bentoo -
trufflehog-3.94.2~amd64 ~arm64
View
Download
Browse License: AGPL-3 Overlay: phoenix591 -
trufflehog-3.93.1~amd64 ~arm64
View
Download
Browse License: AGPL-3 Overlay: phoenix591 -
trufflehog-3.90.11~amd64 ~arm64
View
Download
Browse License: AGPL-3 Overlay: phoenix591
ChangeLog
commit 3d54e2b69dec2a49e62250157d6c88f92d6a2b68
Author: lucascouts <lucascs@protonmail.com>
Date: Thu Sep 24 14:24:16 2026 -0300
bump: doctl, devin-desktop-bin, zed, sentry-native, cline-bin, trufflehog, vulkan-layers, ik_llama-cpp, ollama, ollama-bin, opera; add scripts/go-vendor.sh
dev-vcs/trufflehog 3.97.9 changed go.mod (go-osc52, mimetype), so the
reused 3.97.5 vendor tree no longer matched and -mod=vendor would fail.
Regenerate the vendor tarball for 3.97.9 (uploaded to distfiles.obentoo.org)
and point VENDOR_P at it.
scripts/go-vendor.sh checks whether a Go package's hosted vendor tarball
still matches its go.mod (--check exits 1 when stale) and regenerates it
otherwise. The autoupdate applier cannot see this; run it after bumping any
vendor-tarball Go package. Records and CLAUDE.md point to it; the reviewdog
record no longer claims a vendor tarball it does not use.
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
commit 2cbedff9af5bc00bab93d6d6a0077909a908828f
Author: lucascouts <lucascs@protonmail.com>
Date: Wed Sep 23 16:45:12 2026 -0300
dev-vcs/trufflehog: move reused vendor tree in src_unpack
3.97.8 reuses the 3.97.5 vendor tarball, which unpacks to
$/trufflehog-3.97.5/vendor, not $/vendor.
go-module_src_unpack only skips `go mod verify` when $/vendor exists
right after unpack, so moving it in src_prepare came one phase too late:
the unpack phase reached for proxy.golang.org and died under the network
sandbox.
Move the tree in a custom src_unpack before that check and inherit go-env
for go-env_set_compile_environment. Nothing ever merged, so no revbump.
Also drop the md5-cache entries left behind by 3.97.5 and 3.97.6.
Verified: unpack through compile offline, no `go mod verify` in the log,
binary reports 3.97.8; pkgcheck clean.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
commit 411c9c7a0d28e074dca09d1a95c24ea1d5d0b112
Author: lucascouts <lucascs@protonmail.com>
Date: Wed Sep 23 16:21:47 2026 -0300
add(metadata/{md5-cache/app-editors/zed-1.23.0_pre20260923, md5-cache/app-editors/zed-bin-1.21.0, md5-cache/app-editors/zed-bin-1.22.0_pre, md5-cache/dev-util/claude-agent-acp-plus-0.20.1, md5-cache/dev-util/claude-agent-acp-tui-0.14.0, md5-cache/dev-util/goose-1.52.0, md5-cache/dev-util/goose-bin-1.52.0, md5-cache/dev-util/spirv-headers-1.4.357.0_p20260923, md5-cache/dev-vcs/trufflehog-3.97.8, md5-cache/sci-ml/lemonade-2026.39.1, md5-cache/sci-ml/lemonade-bin-2026.39.1, md5-cache/sys-apps/ai-jail-2.1.0, md5-cache/sys-apps/ai-jail-bin-2.1.0, md5-cache/sys-apps/pnpm-12.6.0}), mod(.autoupdate/packages.toml), up(app-editors/{zed-1.22.0_pre20260923-r1 -> 1.23.0_pre20260923, zed-bin-1.20.2 -> 1.21.0, zed-bin-1.21.0_pre -> 1.22.0_pre}, dev-util/goose{,-bin}-1.51.0 -> 1.52.0, dev-vcs/trufflehog-3.97.6 -> 3.97.8, sci-ml/{lemonade-11.9.0-r1 -> 2026.39.1, lemonade-bin-11.9.0 -> 2026.39.1}, sys-apps/ai-jail{,-bin}-2.0.0 -> 2.1.0)
commit 7f0a77ba856213dd77742ab8974adab270272cf9
Author: lucascouts <lucascs@protonmail.com>
Date: Tue Sep 22 20:12:34 2026 -0300
dev-vcs/trufflehog: fix Manifest for the published 3.97.6 vendor tarball
The 3.97.6 bump recorded a DIST entry for trufflehog-3.97.6-vendor.tar.xz
that was never published to distfiles.obentoo.org, so every fetch 404ed.
The tarball behind those checksums is gone, and `tar -cJf` records mtimes,
so it cannot be reproduced byte for byte.
Regenerated the vendored tree with `go mod vendor`, packed it with the same
layout as 3.97.5 (trufflehog-3.97.6/vendor/), published it to the R2 bucket
and realigned the Manifest with the checksums of what is actually served.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
commit b8d35f084c1155b1f7b4a65664827fc59b7ebe26
Author: lucascouts <lucascs@protonmail.com>
Date: Tue Sep 22 19:50:21 2026 -0300
add(metadata/{md5-cache/app-admin/awscli2-2.37.0, md5-cache/app-admin/doctl-1.171.0, md5-cache/app-editors/cursor-3.21.18, md5-cache/app-misc/claude-desktop-bin-2.2553.13, md5-cache/app-portage/bentoolkit-0.31.1, md5-cache/dev-cpp/simdutf-9.2.0, md5-cache/dev-libs/sentry-native-0.17.0, md5-cache/dev-python/openai-3.18.0, md5-cache/dev-util/antigravity-hub-bin-2.16.0.4917332007583744, md5-cache/dev-util/claude-agent-acp-plus-0.19.0, md5-cache/dev-util/claude-agent-acp-tui-0.13.3, md5-cache/dev-util/claude-code-2.1.280, md5-cache/dev-util/codex-0.156.0, md5-cache/dev-util/codex-bin-0.156.0, md5-cache/dev-util/codex-desktop-bin-26.917.51856, md5-cache/dev-util/copilot-cli-bin-1.0.88, md5-cache/dev-util/glslang-1.4.357.0_p20260922, md5-cache/dev-util/qwen-code-0.24.4, md5-cache/dev-util/spirv-tools-1.4.357.0_p20260922, md5-cache/dev-util/vulkan-utility-libraries-1.4.363_p20260922, md5-cache/dev-vcs/trufflehog-3.97.6, md5-cache/media-libs/vulkan-loader-1.4.363_p20260922, md5-cache/net-misc/modemmanager-1.25.95_p20260922, md5-cache/sci-ml/ollama-bin-0.34.3, md5-cache/www-client/chromium-154.0.8037.57, md5-cache/www-client/librewolf-bin-156.0.1_p1}), mod(.autoupdate/packages.toml), up(app-admin/{awscli2-2.36.50 -> 2.37.0, doctl-1.170.0 -> 1.171.0}, app-editors/cursor-3.21.16 -> 3.21.18, app-misc/claude-desktop-bin-2.2553.1 -> 2.2553.13, app-portage/bentoolkit-0.31.0 -> 0.31.1, dev-cpp/simdutf-9.0.0-r1 -> 9.2.0, dev-libs/sentry-native-0.16.8 -> 0.17.0, dev-python/openai-3.17.0 -> 3.18.0, dev-util/codex{,-bin}-0.155.1 -> 0.156.0, dev-vcs/trufflehog-3.97.5 -> 3.97.6, media-libs/vulkan-loader-1.4.363_p20260921 -> 1.4.363_p20260922, net-misc/modemmanager-1.25.95_p20260920 -> 1.25.95_p20260922, sci-ml/ollama-bin-0.34.2 -> 0.34.3, www-client/{chromium-153.0.8010.52 -> 154.0.8037.57, librewolf-bin-156.0_p1 -> 156.0.1_p1})
commit cd631aeb82cf3004b6097b922f3342a3f5d4b7bf
Author: lucascouts <lucascs@protonmail.com>
Date: Wed Sep 16 18:34:40 2026 -0300
add(metadata/{md5-cache/app-admin/awscli2-2.36.47, md5-cache/app-editors/devin-desktop-bin-3.10.31, md5-cache/app-editors/vim-9.2.1116, md5-cache/app-editors/vim-core-9.2.1116, md5-cache/app-editors/zed-1.22.0_pre20260916, md5-cache/app-editors/zed-bin-1.20.1, md5-cache/app-editors/zed-bin-1.21.0_pre, md5-cache/dev-util/ai-memory-2.3.0, md5-cache/dev-util/ai-memory-bin-2.3.0, md5-cache/dev-util/glslang-1.4.357.0_p20260916, md5-cache/dev-vcs/trufflehog-3.97.5, md5-cache/net-analyzer/netdata-2.11.1, md5-cache/net-libs/nodejs-26.9.0, md5-cache/net-p2p/bisq-bin-1.10.8, md5-cache/www-client/brave-browser-1.95.102}), mod(.autoupdate/packages.toml), up(app-admin/awscli2-2.36.46 -> 2.36.47, app-editors/{devin-desktop-bin-3.10.27 -> 3.10.31, vim-9.2.1112 -> 9.2.1116, vim-core-9.2.1112 -> 9.2.1116, zed-1.21.0_pre20260916 -> 1.22.0_pre20260916, zed-bin-1.19.2 -> 1.20.1, zed-bin-1.20.1_pre -> 1.21.0_pre}, dev-util/ai-memory{,-bin}-2.2.2 -> 2.3.0, dev-vcs/trufflehog-3.97.4 -> 3.97.5, net-analyzer/netdata-2.11.0 -> 2.11.1, net-libs/nodejs-26.8.2 -> 26.9.0, net-p2p/bisq-bin-1.10.7 -> 1.10.8, www-client/brave-browser-1.95.101 -> 1.95.102)
commit 1d108753cf613636bce908fb7eda66c48c13bb50
Author: lucascouts <lucascs@protonmail.com>
Date: Fri Sep 11 22:21:03 2026 -0300
add(app-benchmarks/vegeta-12.13.0, app-misc/watchexec-2.7.2, dev-go/govulncheck-1.8.0, dev-util/{ast-grep-0.45.3, cargo-fuzz-0.13.2, cargo-geiger-0.13.0, cargo-llvm-cov-0.9.1, cargo-mutants-27.1.0, reviewdog-0.21.0, shfmt-3.14.1, tokei-15.0.0}, dev-vcs/trufflehog-3.97.4, net-analyzer/nuclei-3.11.1), mod(.autoupdate/packages.toml)
Thirteen Rust and Go developer tools, none of which ::gentoo carries. Two
new categories: app-benchmarks (vegeta, next to ::gentoo's hey/wrk/siege)
and dev-go (govulncheck, next to ::gentoo's delve/gopls).
Only three existed anywhere: watchexec and tokei in guru, nuclei in pentoo.
Those three are derived from those ebuilds and moved forward -- watchexec
2.5.0 -> 2.7.2, tokei 14 -> 15, nuclei 3.11.0 -> 3.11.1 -- with CRATES
regenerated and ~arm64 added, which guru does not keyword. The other ten
are new.
DEPENDENCY RESOLUTION, AND WHY IT DIFFERS FROM dev-vcs/gitleaks
The six Go packages take a `go mod vendor` tarball hosted on
distfiles.obentoo.org as a second SRC_URI, the shape ::gentoo uses for
dev-go/golangci-lint. gitleaks, the overlay's existing Go package, instead
sets RESTRICT=network-sandbox and runs `ego mod download` at build time --
which pulls code off the network with nothing in the Manifest to check it
against. Here every dependency is covered by a Manifest checksum and the
build stays inside the sandbox. The cost is a tarball to regenerate on each
bump; every autoupdate record says so.
govulncheck: PROBE THE TAGS, NOT THE RELEASES
golang/vuln stopped publishing GitHub releases at v1.1.4 (January 2025) but
kept tagging; the current tag is v1.8.0, from three days ago. Pinning what
releases/latest reports is not merely stale, it is broken: v1.1.4 carries
golang.org/x/tools v0.29.0, which predates the Go 1.27 AST and panics with
"unexpected expr: *ast.KeyValueExpr" on any modern tree. Measured on four
projects before switching the record to rank tags.
This is the mirror image of the trap documented at the top of packages.toml,
where ranking tags is what misleads. Both records now state which endpoint
lies and why -- watchexec is the opposite case in the same commit: its tag
space is shared with a library crate sitting six majors ahead
(watchexec-v8.4.1 against CLI v2.7.2), so there the release endpoint is the
only safe one.
FOUND BY LOOKING AT THE INSTALLED IMAGE, NOT THE EBUILD
* ast-grep also installs a binary named `sg`, straight on top of
/usr/bin/sg from sys-apps/shadow -- a symlink to newgrp, base system. The
ebuild removes it, guarded so upstream dropping the binary fails loudly
rather than silently changing what ships.
* shfmt and govulncheck both report their version through
debug.ReadBuildInfo(), which for a tarball build says "(devel)". They
installed fine and then could not name themselves: `shfmt --version` said
"(devel)" and the scanner called itself govulncheck@v0.0.0, in output
people paste into reports. One patch each, in files/.
LICENSING
nuclei is MIT but statically links github.com/projectdiscovery/ldapserver,
which is GPL-2, so the binary is effectively GPL-2 and LICENSE says so. The
HashiCorp dependencies that first looked AGPL are not: the MPL-2.0 text
names the AGPL in its Secondary License clause.
cargo-llvm-cov drops its test-helper dev-dependency in src_prepare. It is a
git dependency pinned by rev, and cargo.eclass's [patch] entry does not
substitute a git source pinned that way, so cargo reaches for the network
even with the tarball unpacked beside it. Since cargo resolves the whole
graph before it knows only the binary is wanted, the dependency has to go;
the suite that uses it is restricted.
SECURITY REVIEW
Reachability analysis with govulncheck 1.8.0 rather than dependency-level
counting alone -- roughly half the declared findings are not reachable:
shfmt 0, govulncheck 0, vegeta 3 of 7, reviewdog 4 of 7, nuclei 5 of 8,
trufflehog 6 of 11. Rust side, osv-scanner over Cargo.lock: watchexec
clean, ast-grep 1, cargo-fuzz 2, cargo-llvm-cov 2, cargo-mutants 5, tokei
16, and cargo-geiger 62 across 40 packages -- it has not released since
August 2025 and carries cargo 0.86 against 0.97. No dependency was bumped
away from upstream: that would diverge the tree and break the next bump.
VERIFIED LOCALLY, NOTHING MERGED (host has no sudo)
All thirteen built and installed through `ebuild ... clean install` under a
PORTAGE_CONFIGROOT with the four unprivileged overrides; pkgcheck
--cache=no is clean on all thirteen; every md5-cache _md5_ matches its
ebuild; all thirteen autoupdate records were probed against the live
endpoint and agree with the packaged version.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Author: lucascouts <lucascs@protonmail.com>
Date: Thu Sep 24 14:24:16 2026 -0300
bump: doctl, devin-desktop-bin, zed, sentry-native, cline-bin, trufflehog, vulkan-layers, ik_llama-cpp, ollama, ollama-bin, opera; add scripts/go-vendor.sh
dev-vcs/trufflehog 3.97.9 changed go.mod (go-osc52, mimetype), so the
reused 3.97.5 vendor tree no longer matched and -mod=vendor would fail.
Regenerate the vendor tarball for 3.97.9 (uploaded to distfiles.obentoo.org)
and point VENDOR_P at it.
scripts/go-vendor.sh checks whether a Go package's hosted vendor tarball
still matches its go.mod (--check exits 1 when stale) and regenerates it
otherwise. The autoupdate applier cannot see this; run it after bumping any
vendor-tarball Go package. Records and CLAUDE.md point to it; the reviewdog
record no longer claims a vendor tarball it does not use.
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
commit 2cbedff9af5bc00bab93d6d6a0077909a908828f
Author: lucascouts <lucascs@protonmail.com>
Date: Wed Sep 23 16:45:12 2026 -0300
dev-vcs/trufflehog: move reused vendor tree in src_unpack
3.97.8 reuses the 3.97.5 vendor tarball, which unpacks to
$/trufflehog-3.97.5/vendor, not $/vendor.
go-module_src_unpack only skips `go mod verify` when $/vendor exists
right after unpack, so moving it in src_prepare came one phase too late:
the unpack phase reached for proxy.golang.org and died under the network
sandbox.
Move the tree in a custom src_unpack before that check and inherit go-env
for go-env_set_compile_environment. Nothing ever merged, so no revbump.
Also drop the md5-cache entries left behind by 3.97.5 and 3.97.6.
Verified: unpack through compile offline, no `go mod verify` in the log,
binary reports 3.97.8; pkgcheck clean.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
commit 411c9c7a0d28e074dca09d1a95c24ea1d5d0b112
Author: lucascouts <lucascs@protonmail.com>
Date: Wed Sep 23 16:21:47 2026 -0300
add(metadata/{md5-cache/app-editors/zed-1.23.0_pre20260923, md5-cache/app-editors/zed-bin-1.21.0, md5-cache/app-editors/zed-bin-1.22.0_pre, md5-cache/dev-util/claude-agent-acp-plus-0.20.1, md5-cache/dev-util/claude-agent-acp-tui-0.14.0, md5-cache/dev-util/goose-1.52.0, md5-cache/dev-util/goose-bin-1.52.0, md5-cache/dev-util/spirv-headers-1.4.357.0_p20260923, md5-cache/dev-vcs/trufflehog-3.97.8, md5-cache/sci-ml/lemonade-2026.39.1, md5-cache/sci-ml/lemonade-bin-2026.39.1, md5-cache/sys-apps/ai-jail-2.1.0, md5-cache/sys-apps/ai-jail-bin-2.1.0, md5-cache/sys-apps/pnpm-12.6.0}), mod(.autoupdate/packages.toml), up(app-editors/{zed-1.22.0_pre20260923-r1 -> 1.23.0_pre20260923, zed-bin-1.20.2 -> 1.21.0, zed-bin-1.21.0_pre -> 1.22.0_pre}, dev-util/goose{,-bin}-1.51.0 -> 1.52.0, dev-vcs/trufflehog-3.97.6 -> 3.97.8, sci-ml/{lemonade-11.9.0-r1 -> 2026.39.1, lemonade-bin-11.9.0 -> 2026.39.1}, sys-apps/ai-jail{,-bin}-2.0.0 -> 2.1.0)
commit 7f0a77ba856213dd77742ab8974adab270272cf9
Author: lucascouts <lucascs@protonmail.com>
Date: Tue Sep 22 20:12:34 2026 -0300
dev-vcs/trufflehog: fix Manifest for the published 3.97.6 vendor tarball
The 3.97.6 bump recorded a DIST entry for trufflehog-3.97.6-vendor.tar.xz
that was never published to distfiles.obentoo.org, so every fetch 404ed.
The tarball behind those checksums is gone, and `tar -cJf` records mtimes,
so it cannot be reproduced byte for byte.
Regenerated the vendored tree with `go mod vendor`, packed it with the same
layout as 3.97.5 (trufflehog-3.97.6/vendor/), published it to the R2 bucket
and realigned the Manifest with the checksums of what is actually served.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
commit b8d35f084c1155b1f7b4a65664827fc59b7ebe26
Author: lucascouts <lucascs@protonmail.com>
Date: Tue Sep 22 19:50:21 2026 -0300
add(metadata/{md5-cache/app-admin/awscli2-2.37.0, md5-cache/app-admin/doctl-1.171.0, md5-cache/app-editors/cursor-3.21.18, md5-cache/app-misc/claude-desktop-bin-2.2553.13, md5-cache/app-portage/bentoolkit-0.31.1, md5-cache/dev-cpp/simdutf-9.2.0, md5-cache/dev-libs/sentry-native-0.17.0, md5-cache/dev-python/openai-3.18.0, md5-cache/dev-util/antigravity-hub-bin-2.16.0.4917332007583744, md5-cache/dev-util/claude-agent-acp-plus-0.19.0, md5-cache/dev-util/claude-agent-acp-tui-0.13.3, md5-cache/dev-util/claude-code-2.1.280, md5-cache/dev-util/codex-0.156.0, md5-cache/dev-util/codex-bin-0.156.0, md5-cache/dev-util/codex-desktop-bin-26.917.51856, md5-cache/dev-util/copilot-cli-bin-1.0.88, md5-cache/dev-util/glslang-1.4.357.0_p20260922, md5-cache/dev-util/qwen-code-0.24.4, md5-cache/dev-util/spirv-tools-1.4.357.0_p20260922, md5-cache/dev-util/vulkan-utility-libraries-1.4.363_p20260922, md5-cache/dev-vcs/trufflehog-3.97.6, md5-cache/media-libs/vulkan-loader-1.4.363_p20260922, md5-cache/net-misc/modemmanager-1.25.95_p20260922, md5-cache/sci-ml/ollama-bin-0.34.3, md5-cache/www-client/chromium-154.0.8037.57, md5-cache/www-client/librewolf-bin-156.0.1_p1}), mod(.autoupdate/packages.toml), up(app-admin/{awscli2-2.36.50 -> 2.37.0, doctl-1.170.0 -> 1.171.0}, app-editors/cursor-3.21.16 -> 3.21.18, app-misc/claude-desktop-bin-2.2553.1 -> 2.2553.13, app-portage/bentoolkit-0.31.0 -> 0.31.1, dev-cpp/simdutf-9.0.0-r1 -> 9.2.0, dev-libs/sentry-native-0.16.8 -> 0.17.0, dev-python/openai-3.17.0 -> 3.18.0, dev-util/codex{,-bin}-0.155.1 -> 0.156.0, dev-vcs/trufflehog-3.97.5 -> 3.97.6, media-libs/vulkan-loader-1.4.363_p20260921 -> 1.4.363_p20260922, net-misc/modemmanager-1.25.95_p20260920 -> 1.25.95_p20260922, sci-ml/ollama-bin-0.34.2 -> 0.34.3, www-client/{chromium-153.0.8010.52 -> 154.0.8037.57, librewolf-bin-156.0_p1 -> 156.0.1_p1})
commit cd631aeb82cf3004b6097b922f3342a3f5d4b7bf
Author: lucascouts <lucascs@protonmail.com>
Date: Wed Sep 16 18:34:40 2026 -0300
add(metadata/{md5-cache/app-admin/awscli2-2.36.47, md5-cache/app-editors/devin-desktop-bin-3.10.31, md5-cache/app-editors/vim-9.2.1116, md5-cache/app-editors/vim-core-9.2.1116, md5-cache/app-editors/zed-1.22.0_pre20260916, md5-cache/app-editors/zed-bin-1.20.1, md5-cache/app-editors/zed-bin-1.21.0_pre, md5-cache/dev-util/ai-memory-2.3.0, md5-cache/dev-util/ai-memory-bin-2.3.0, md5-cache/dev-util/glslang-1.4.357.0_p20260916, md5-cache/dev-vcs/trufflehog-3.97.5, md5-cache/net-analyzer/netdata-2.11.1, md5-cache/net-libs/nodejs-26.9.0, md5-cache/net-p2p/bisq-bin-1.10.8, md5-cache/www-client/brave-browser-1.95.102}), mod(.autoupdate/packages.toml), up(app-admin/awscli2-2.36.46 -> 2.36.47, app-editors/{devin-desktop-bin-3.10.27 -> 3.10.31, vim-9.2.1112 -> 9.2.1116, vim-core-9.2.1112 -> 9.2.1116, zed-1.21.0_pre20260916 -> 1.22.0_pre20260916, zed-bin-1.19.2 -> 1.20.1, zed-bin-1.20.1_pre -> 1.21.0_pre}, dev-util/ai-memory{,-bin}-2.2.2 -> 2.3.0, dev-vcs/trufflehog-3.97.4 -> 3.97.5, net-analyzer/netdata-2.11.0 -> 2.11.1, net-libs/nodejs-26.8.2 -> 26.9.0, net-p2p/bisq-bin-1.10.7 -> 1.10.8, www-client/brave-browser-1.95.101 -> 1.95.102)
commit 1d108753cf613636bce908fb7eda66c48c13bb50
Author: lucascouts <lucascs@protonmail.com>
Date: Fri Sep 11 22:21:03 2026 -0300
add(app-benchmarks/vegeta-12.13.0, app-misc/watchexec-2.7.2, dev-go/govulncheck-1.8.0, dev-util/{ast-grep-0.45.3, cargo-fuzz-0.13.2, cargo-geiger-0.13.0, cargo-llvm-cov-0.9.1, cargo-mutants-27.1.0, reviewdog-0.21.0, shfmt-3.14.1, tokei-15.0.0}, dev-vcs/trufflehog-3.97.4, net-analyzer/nuclei-3.11.1), mod(.autoupdate/packages.toml)
Thirteen Rust and Go developer tools, none of which ::gentoo carries. Two
new categories: app-benchmarks (vegeta, next to ::gentoo's hey/wrk/siege)
and dev-go (govulncheck, next to ::gentoo's delve/gopls).
Only three existed anywhere: watchexec and tokei in guru, nuclei in pentoo.
Those three are derived from those ebuilds and moved forward -- watchexec
2.5.0 -> 2.7.2, tokei 14 -> 15, nuclei 3.11.0 -> 3.11.1 -- with CRATES
regenerated and ~arm64 added, which guru does not keyword. The other ten
are new.
DEPENDENCY RESOLUTION, AND WHY IT DIFFERS FROM dev-vcs/gitleaks
The six Go packages take a `go mod vendor` tarball hosted on
distfiles.obentoo.org as a second SRC_URI, the shape ::gentoo uses for
dev-go/golangci-lint. gitleaks, the overlay's existing Go package, instead
sets RESTRICT=network-sandbox and runs `ego mod download` at build time --
which pulls code off the network with nothing in the Manifest to check it
against. Here every dependency is covered by a Manifest checksum and the
build stays inside the sandbox. The cost is a tarball to regenerate on each
bump; every autoupdate record says so.
govulncheck: PROBE THE TAGS, NOT THE RELEASES
golang/vuln stopped publishing GitHub releases at v1.1.4 (January 2025) but
kept tagging; the current tag is v1.8.0, from three days ago. Pinning what
releases/latest reports is not merely stale, it is broken: v1.1.4 carries
golang.org/x/tools v0.29.0, which predates the Go 1.27 AST and panics with
"unexpected expr: *ast.KeyValueExpr" on any modern tree. Measured on four
projects before switching the record to rank tags.
This is the mirror image of the trap documented at the top of packages.toml,
where ranking tags is what misleads. Both records now state which endpoint
lies and why -- watchexec is the opposite case in the same commit: its tag
space is shared with a library crate sitting six majors ahead
(watchexec-v8.4.1 against CLI v2.7.2), so there the release endpoint is the
only safe one.
FOUND BY LOOKING AT THE INSTALLED IMAGE, NOT THE EBUILD
* ast-grep also installs a binary named `sg`, straight on top of
/usr/bin/sg from sys-apps/shadow -- a symlink to newgrp, base system. The
ebuild removes it, guarded so upstream dropping the binary fails loudly
rather than silently changing what ships.
* shfmt and govulncheck both report their version through
debug.ReadBuildInfo(), which for a tarball build says "(devel)". They
installed fine and then could not name themselves: `shfmt --version` said
"(devel)" and the scanner called itself govulncheck@v0.0.0, in output
people paste into reports. One patch each, in files/.
LICENSING
nuclei is MIT but statically links github.com/projectdiscovery/ldapserver,
which is GPL-2, so the binary is effectively GPL-2 and LICENSE says so. The
HashiCorp dependencies that first looked AGPL are not: the MPL-2.0 text
names the AGPL in its Secondary License clause.
cargo-llvm-cov drops its test-helper dev-dependency in src_prepare. It is a
git dependency pinned by rev, and cargo.eclass's [patch] entry does not
substitute a git source pinned that way, so cargo reaches for the network
even with the tarball unpacked beside it. Since cargo resolves the whole
graph before it knows only the binary is wanted, the dependency has to go;
the suite that uses it is restricted.
SECURITY REVIEW
Reachability analysis with govulncheck 1.8.0 rather than dependency-level
counting alone -- roughly half the declared findings are not reachable:
shfmt 0, govulncheck 0, vegeta 3 of 7, reviewdog 4 of 7, nuclei 5 of 8,
trufflehog 6 of 11. Rust side, osv-scanner over Cargo.lock: watchexec
clean, ast-grep 1, cargo-fuzz 2, cargo-llvm-cov 2, cargo-mutants 5, tokei
16, and cargo-geiger 62 across 40 packages -- it has not released since
August 2025 and carries cargo 0.86 against 0.97. No dependency was bumped
away from upstream: that would diverge the tree and break the next bump.
VERIFIED LOCALLY, NOTHING MERGED (host has no sudo)
All thirteen built and installed through `ebuild ... clean install` under a
PORTAGE_CONFIGROOT with the four unprivileged overrides; pkgcheck
--cache=no is clean on all thirteen; every md5-cache _md5_ matches its
ebuild; all thirteen autoupdate records were probed against the live
endpoint and agree with the packaged version.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

