taco-lib
The shared Go library used across the TACO ecosystem. Provides the vulnerability database engine, matching logic, and common types.
The shared Go library used across the TACO ecosystem. Provides the vulnerability database engine, matching logic, and common types.
Overview
| Property | Value |
|---|---|
| Language | Go |
| Type | Library (imported by other services) |
| Repository | tacosec/taco-lib |
Packages
types/
Core domain types shared across all TACO services.
- Severity -- Enum type:
Unknown,Low,Medium,High,Criticalwith string parsing. - Vulnerability -- Struct representing a matched vulnerability: ID, severity, package, ecosystem, installed version, fixed version, title, description, references, source, known-exploited flag.
vulndb/
The vulnerability database engine. This is the core of the scanning system.
Database Management
| File | Purpose |
|---|---|
cache.go | Local cache management: database path, metadata, staleness checks |
db.go | Database file format: read, write, entry types |
download.go | HTTP download of pre-built databases |
merge.go | Multi-source merging with deduplication and source-priority ordering |
Source Fetchers
Each source implements the SourceFetcher interface (FetchAll and FetchRecent):
| File | Source | Description |
|---|---|---|
fetch.go | Common | Multi-source update orchestration |
fetch_alas.go | ALAS | Amazon Linux Security Advisories |
fetch_alpine.go | Alpine SecDB | Alpine Linux security database |
fetch_cisa.go | CISA KEV | Known Exploited Vulnerabilities catalog |
fetch_debian.go | Debian | Debian Security Tracker |
fetch_ghsa.go | GHSA | GitHub Security Advisories (GraphQL API) |
fetch_osv.go | OSV | Open Source Vulnerabilities |
fetch_redhat.go | Red Hat | Red Hat Security Data API |
fetch_ubuntu.go | Ubuntu | Ubuntu Security Notices |
Matching
| File | Purpose |
|---|---|
match.go | Version-range matching: compares a package URL against vulnerability entries |
source.go | Source names, priority ordering, default source list |
Distribution
| File | Purpose |
|---|---|
oci.go | Push/pull database as OCI artifacts to container registries |
serve.go | HTTP server for hosting the database |
Networking
| File | Purpose |
|---|---|
httpclient.go | Shared HTTP client with retries and rate limiting |
Source Priority System
The library defines 9 vulnerability sources with a priority order. When merging data from multiple sources, if the same vulnerability appears for the same package and ecosystem from multiple sources, the entry from the higher-priority source takes precedence.
Priority (highest to lowest): Alpine SecDB > Debian > Ubuntu > Red Hat > ALAS > GHSA > OSV > NVD > CISA KEV.
Consumed By
- taco-scanner -- Uses
vulndbfor loading the database and matching components - taco-vulndb -- Uses
vulndbfor all CLI operations (update, build, export, serve, push, pull) - taco-scanner/updater -- Uses
vulndbfor background database updates