Making this for visibility, feel free to edit and reframe
When osv-scalibr started to use a CGO library due to google/osv-scalibr#1405, it broke Goreleaser. @erikvarga managed to replace the library in osv-scalibr, but has indicated it's unlikely we can avoid having CGO libraries in scalibr forever :
However, we have another PRP contribution that would like to use the library in a way that's harder to reimplement with just regexp parsing: google/osv-scalibr#1444
This issue is to track how we deal with that
Making this for visibility, feel free to edit and reframe
When
osv-scalibrstarted to use a CGO library due to google/osv-scalibr#1405, it broke Goreleaser. @erikvarga managed to replace the library inosv-scalibr, but has indicated it's unlikely we can avoid having CGO libraries in scalibr forever :This issue is to track how we deal with that