taco-lib

The shared Go library used across the TACO ecosystem. Provides the vulnerability database engine, matching logic, and common types.

The shared Go library used across the TACO ecosystem. Provides the vulnerability database engine, matching logic, and common types.

Overview

PropertyValue
LanguageGo
TypeLibrary (imported by other services)
Repositorytacosec/taco-lib

Packages

types/

Core domain types shared across all TACO services.

  • Severity -- Enum type: Unknown, Low, Medium, High, Critical with string parsing.
  • Vulnerability -- Struct representing a matched vulnerability: ID, severity, package, ecosystem, installed version, fixed version, title, description, references, source, known-exploited flag.

vulndb/

The vulnerability database engine. This is the core of the scanning system.

Database Management

FilePurpose
cache.goLocal cache management: database path, metadata, staleness checks
db.goDatabase file format: read, write, entry types
download.goHTTP download of pre-built databases
merge.goMulti-source merging with deduplication and source-priority ordering

Source Fetchers

Each source implements the SourceFetcher interface (FetchAll and FetchRecent):

FileSourceDescription
fetch.goCommonMulti-source update orchestration
fetch_alas.goALASAmazon Linux Security Advisories
fetch_alpine.goAlpine SecDBAlpine Linux security database
fetch_cisa.goCISA KEVKnown Exploited Vulnerabilities catalog
fetch_debian.goDebianDebian Security Tracker
fetch_ghsa.goGHSAGitHub Security Advisories (GraphQL API)
fetch_osv.goOSVOpen Source Vulnerabilities
fetch_redhat.goRed HatRed Hat Security Data API
fetch_ubuntu.goUbuntuUbuntu Security Notices

Matching

FilePurpose
match.goVersion-range matching: compares a package URL against vulnerability entries
source.goSource names, priority ordering, default source list

Distribution

FilePurpose
oci.goPush/pull database as OCI artifacts to container registries
serve.goHTTP server for hosting the database

Networking

FilePurpose
httpclient.goShared HTTP client with retries and rate limiting

Source Priority System

The library defines 9 vulnerability sources with a priority order. When merging data from multiple sources, if the same vulnerability appears for the same package and ecosystem from multiple sources, the entry from the higher-priority source takes precedence.

Priority (highest to lowest): Alpine SecDB > Debian > Ubuntu > Red Hat > ALAS > GHSA > OSV > NVD > CISA KEV.

Consumed By

  • taco-scanner -- Uses vulndb for loading the database and matching components
  • taco-vulndb -- Uses vulndb for all CLI operations (update, build, export, serve, push, pull)
  • taco-scanner/updater -- Uses vulndb for background database updates