-
Notifications
You must be signed in to change notification settings - Fork 130
/
Copy patho.yaml
205 lines (204 loc) · 25 KB
/
o.yaml
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
# vim: tabstop=39 expandtab softtabstop=39 nomodeline
- { name: obfsproxy, verpat: "[0-9]{3}", incorrect: true }
- { name: objconv, verpat: "20[0-9]{2}.*", incorrect: true } # macosx, homebrew
- { name: obmenu, ver: "2.0", ruleset: bunsenlabs, incorrect: true } # fake
- { name: obs-service-download-files, verpat: "20[0-9]{6}", incorrect: true }
- { name: obs-service-download-url, verpat: "20[0-9]{6}", incorrect: true }
- { name: obs-service-verify-file, verpat: "20[0-9]{6}", incorrect: true }
- { name: obs-studio, ruleset: t2, untrusted: true } # accused of fake 32.2.1
- { name: obs-studio, ver: "29.3.1", ruleset: pisi, incorrect: true }
- { name: obs-studio, ruleset: pisi, untrusted: true } # accused of fake 29.3.1
- { name: obuparse, noscheme: true }
- { name: "ocaml:bin-prot", ver: "2.0.9", ruleset: fedora, incorrect: true }
- { name: "ocaml:bin-prot", ruleset: fedora, untrusted: true } # accused of fake 2.0.9
- { name: "ocaml:bin-prot", verge: "100", sink: true } # ... -> 113.x → 0.9.0
- { name: "ocaml:calendar", ver: "2.5", ruleset: nix, incorrect: true }
- { name: "ocaml:calendar", ruleset: nix, untrusted: true } # accused of fake 2.5 (it's really 2.03.2)
- { name: "ocaml:cryptokit", ver: "1.161", incorrect: true } # 1.16.1
- { name: "ocaml:cryptokit", ruleset: gentoo, untrusted: true } # accused of fake 1.161
- { name: "ocaml:cryptokit", ver: "1161", incorrect: true } # 1.16.1
- { name: "ocaml:cryptokit", ruleset: rosa, untrusted: true } # accused of fake 1161
- { name: "ocaml:libvirt", verpat: ".*unstable", incorrect: true } # nix garbage
- { name: "ocaml:ocamlfuse", verpat: ".*cvs[0-9]+", any_is_patch: true, ignore: false } # official versioning scheme https://github.com/astrada/ocamlfuse/tags
- { name: "ocaml:opam-file-format", ruleset: sisyphus, untrusted: true }
- { name: "ocaml:sexplib", ver: "7.0.5", ruleset: fedora, incorrect: true }
- { name: "ocaml:sexplib", ruleset: fedora, untrusted: true } # accused of fake 7.0.5
- { name: "ocaml:sexplib", verge: "100", sink: true } # ... -> 113.x → 0.9.0
- { name: "ocaml:textutils", verge: "100", sink: true } # ... -> 113.x → 0.9.0
- { name: "ocaml:variantslib", verge: "100", sink: true } # ... -> 113.x → 0.9.0
- { name: "ocaml:yojson", verpat: ".+20[0-9]{6}", snapshot: true }
- { name: oclgrind, verpat: "20[0-9]{6}", incorrect: true }
- { name: ocropus, verpat: "20[0-9]{6}", incorrect: true }
- { name: octave, verpat: ".*pre[0-9]{5}", snapshot: true }
- { name: octave, verpat: "[0-9]+\\.[0-9]+\\.9[0-9]+", devel: true } # rc's https://hg.savannah.gnu.org/hgweb/octave/tags
- { name: "octave:biosig", ver: "3.0.1", ruleset: freebsd, incorrect: true }
- { name: "octave:biosig", ruleset: freebsd, untrusted: true } # accused of fake 3.0.1
- { name: "octave:secs1d", verpat: ".*r.*", snapshot: true }
- { name: "octave:secs2d", verpat: ".*r.*", snapshot: true }
- { namepat: "octetos-.*", ruleset: aur, untrusted: true } # strips alpha/beta suffix
- { name: octomap, verpat: "[0-9a-f]{40}", incorrect: true } # commit hash
- { name: odin-lang, verpat: ".*20[0-9]{2}.*", devel: true }
- { name: odoo, verpat: ".*20[0-9]{6}", snapshot: true }
- { name: odrive-google-drive-client, ver: "1.6.6", ruleset: deepin, incorrect: true }
- { name: odrive-google-drive-client, ruleset: deepin, untrusted: true } # accused of fake 1.6.6
- { name: oggfwd, noscheme: true }
- { name: ogle-gui, verpat: ".*patched.*", incorrect: true }
- { name: ogre, verpat: "2.*", ignore: true }
- { name: oh-my-zsh, noscheme: true }
- { name: oilwar, ruleset: os4depot, incorrect: true }
- { name: okteta, verpat: "(4|14|15|16|17|18).*", sink: true } # went from following KDE versioning to its own 0.x/1.x-based versioning
- { name: okteta, ver: "0.26.60", ruleset: openmandriva, incorrect: true }
- { name: okteta, ruleset: openmandriva, untrusted: true } # accused of fake 0.26.60
- { name: okular, verpat: "[0-9]+\\.[0-9]+\\.[89][0-9]+", devel: true }
- { name: ollydbg, verpat: "[0-9]{3}.*", incorrect: true } # it's 1.10, 2.0, 2.01g
- { name: omega-rpg, releq: "0.90", devel: true } # not sure how wide should the coverage be
- { name: onboard, ver: "1.4.1.12", ruleset: debuntu, incorrect: true } # deepin
- { name: onboard, ruleset: debuntu, untrusted: true } # accused of fake 1.4.1.4
- { name: onevpl, verpat: "202[23].*", sink: true }
- { name: oniguruma, ruleset: openbsd, untrusted: true } # accused of fake 6.9.5pl1
- { name: oniguruma, verpat: ".*rev.*", any_is_patch: true }
- { name: onioncat, verpat: "0\\.2\\.2\\.r[0-9]+.*", any_is_patch: true } # https://www.cypherpunk.at/ocat/download/Source/stable/
- { name: onioncat, ver: "0\\.2\\.2", incorrect: true }
- { name: onlyoffice-documentserver, verlonger: 3, ruleset: freebsd, incorrect: true } # FreeBSD DISTVERSION
- { name: opalang, verpat: "20[0-9]{6}", snapshot: true }
- { name: opalang, verpat: "[0-9]{4}", sink: true } # judging by https://github.com/MLstate/opalang/releases, 1.1.1 is the latest
- { name: opam, ruleset: [sisyphus,mageia], untrusted: true } # accused of fake 2.0.0
- { name: open-adventure, ver: "2.5", ruleset: guix, incorrect: true }
- { name: open-adventure, ruleset: guix, untrusted: true } # accused of fake 2.5
- { name: open-vm-tools, verpat: "20[0-9]{2}.*", snapshot: true }
- { name: open-vm-tools, verpat: "20(08|09|11).*", sink: true }
- { name: open-vm-tools, verpat: ".*[0-9]{8}", altver: true } # used in tarballs, see https://github.com/vmware/open-vm-tools/releases
- { name: open2300, ver: "1.12", ruleset: openwrt, incorrect: true } # latest version is 1.10
- { name: openafs, verpat: ".*-.*", ruleset: nix, incorrect: true } # kernel version appended
- { name: openal-creative, verpat: "20[0-9]{6}.*", incorrect: true }
- { name: openal-creative, verge: "1.15", incorrect: true } # openal-soft
- { name: openaptx, noscheme: true }
- { name: openarena, ruleset: os4depot, incorrect: true }
- { name: openasar, noscheme: true }
- { name: openbgpd, verpat: ".*p.*", ruleset: gentoo, untrusted: false }
- { name: openbor, verpat: ".*[^0-9]([0-9]{4,5})", setver: $1 }
- { name: opencascade-occt, ruleset: debuntu, untrusted: true } # accused of fake 7.3.3
- { name: opencascade-occt, p_is_patch: true } # 7.3.0 < 7.3.0p3
- { name: opencascade-oce, verlonger: 3, incorrect: true } # weird mix of occt and oce versions
- { name: opencascade-oce, verge: "6", incorrect: true } # latest oce version is 0.18.3
- { name: opencity, ver: "0.0.6.5stable", ignore: true } # 0.0.6.5; "stable" is not a part of the version
- { name: opencl, noscheme: true } # GH/KhronosGroup/OpenCL-Headers w/o releases or mix of OpenCL-Headers with OpenCL-CLHPP
- { name: opencl-clhpp, verpat: "20[0-9]{6}", incorrect: true }
- { name: opencl-headers, noscheme: true }
- { name: opencollada, verpat: ".*3335ac.*", incorrect: true }
- { name: opencollada, verpat: "20[0-9]{6}", incorrect: true } # aosc
- { name: opencollada, ver: "1.6.70", incorrect: true } # unofficial, windows-only changes
- { name: opencolorio, verpat: "20[0-9]{6}", incorrect: true }
- { name: opencvs, noscheme: true }
- { name: opendbx, ver: "1.5.0", devel: true } # https://linuxnetworks.de/doc/index.php?title=OpenDBX/Download; XXX probably needs pattern, but the devel scheme is unknown
- { name: opendkim, ver: "2.11.0", ruleset: [rpm,alpine], incorrect: true } # it's 2.11.0.alpha0: https://sourceforge.net/projects/opendkim/files/
- { name: opendkim, ruleset: [rpm,alpine], untrusted: true } # accused of fake 2.11.0
- { name: opendoas, ver: "6.9", ruleset: aur, incorrect: true } # fork using the name of original project
- { name: opendoas, ruleset: aur, untrusted: true } # accused of fake 6.9 from an insecure fork
- { name: openfoam-org, verge: "1800", incorrect: true }
- { name: openjade, verpat: ".*(p|pre|devel)[0-9]*", devel: true }
- { name: openjade, ver: "1.3.3", ruleset: [openpkg,rpm], incorrect: true } # fake, it's 1.3.3pre1
- { name: openjazz, ver: "20190120", incorrect: true } # openbsd (latest is 20190106)
- { name: openjazz, ruleset: openbsd, untrusted: true } # accused of fake 20190120
- { name: openjdk, ruleset: freebsd, untrusted: true } # accused of appending custom component to the upstream release
- { name: openjdk, wwwpart: battleblow, untrusted: true } # accused of appending custom component to the upstream release
- { name: openjdk, ruleset: debuntu, untrusted: true } # debian experimental uses snapshot should be fixed by repology/repology-updater#811
- { name: openjdk, noscheme: true } # tags in jdk-15+36 format, versions in 15.0.1 format, adoptopenjdk versions in 15.0.1+9.1 format
- { name: openjfx, verpat: "8\\.0\\..*", ignore: true } # fedora; the official scheme is e.g. 8u151b12
- { name: openjk, noscheme: true }
- { name: openkim-models, verpat: "20[0-9]{6}", incorrect: true } # it's YYYY-MM-DD
- { name: openlierox, verpat: "20[0-9]{6}.*", incorrect: true }
- { name: openmortal, ver: "0.7.1", ignore: true } # legal release, but no source tarball
- { name: openmpi, verpat: ".*x", incorrect: true } # "use x to avoid epoch" bullshit
- { name: opennap, ver: "0.45", ruleset: hpux, incorrect: true }
- { name: opennap, ruleset: hpux, untrusted: true }
- { name: openntpd, ver: "20080406p", snapshot: true }
- { name: openntpd, p_is_patch: true }
- { name: openocd, verpat: "20[0-9]{6}", incorrect: true } # scoop
- { name: openocd, ver: "0.12.0+1", ruleset: void, incorrect: true }
- { name: openocd, ruleset: void, untrusted: true } # accused of fake 0.12.0+1
- { name: openoffice, verpat: "([0-9]+\\.){2}[0-9]{3}.*", incorrect: true } # winget, freebsd garbage
- { name: openoffice, verpat: "[0-9]+\\.[0-9]{3}.*", incorrect: true } # winget garbage
- { name: openoffice, verpat: ".*[0-9a-f]{10}", incorrect: true }
- { name: openoffice, ruleset: t2, untrusted: true } # accused of fake 4.1.13-281f0d3533
- { name: openomf, ver: "0.6.5.2", ruleset: openbsd, incorrect: true } # latest is 0.6.5
- { name: openomf, ruleset: openbsd, untrusted: true } # accused of fake 0.6.5.2
- { name: openpam, ruleset: openbsd, incorrect: true } # not openpam at all
- { name: openrazer, verpat: ".*-.*", ruleset: nix, incorrect: true } # kernel version appended
- { name: openrct2, ver: "0.4.18.90", incorrect: true }
- { name: openrct2, ruleset: aur, untrusted: true } # accused of fake 0.4.18.90
- { name: openrgb, verpat: ".+20[0-9]{6}", snapshot: true }
- { name: openscad, verlonger: 2, ruleset: freebsd, incorrect: true }
- { name: openscenegraph, verpat: "3\\.[0-9]*[13579]\\..*", devel: true }
- { name: openshot, verlonger: 3, ruleset: freebsd, incorrect: true }
- { name: openshot, ruleset: freebsd, untrusted: true } # accused of fake 2.5.1.7
- { name: openshot, ver: "2.5.2", ruleset: [sisyphus,deb_multimedia], incorrect: true } # probably a misrelease
- { name: opensmtpd, p_is_patch: true }
- { name: opensmtpd-extras, verge: "200000000000", verlt: "201811070000", sink: true } # 6.4.0 from 07 nov 2018
- { name: openssh, verpat: "([0-9]+\\.[0-9]+)\\.([0-9]+)", setver: "$1p$2" } # pkgrc: it's X.YpZ!
- { name: openssh, verpat: "[0-9]+\\.[0-9]+", incorrect: true } # freshcode, pZ part missing
- { name: openssh, verpat: "20[0-9-]{6}.*", snapshot: true } # scoop
- { name: openssh, p_is_patch: true }
- { name: openssh, ruleset: os4depot, incorrect: true }
- { name: openssh, ver: "8.2p1-1", incorrect: true }
- { name: openssh, verlonger: 2, ruleset: scoop, incorrect: true }
- { name: openssh, ruleset: scoop, untrusted: true } # accused of fake 8.9.1.0p1
- { name: openssh, ver: "9.7.1_p1", ruleset: chimera, incorrect: true }
- { name: openssh, ruleset: chimera, untrusted: true } # accused of fake 9.7.1_p1
- { name: openssh, ruleset: scoop, untrusted: true } # accused of fake 8.9.1.0p1
- { name: openssl, verpat: "([0-9]+\\.){2}[0-9]{2,}", incorrect: true } # buckaroo's 1.0.211
- { name: openssl, ruleset: liguros, incorrect: true } # fakes libressl as openssl
- { name: openssl, verpat: "([0-9]+\\.){3}[0-9a-z].*", incorrect: true, vulnerable: true } # 1.1.1.11 or 1.1.1.i
- { name: openssl, verpat: "([0-9]+\\.){2}[0-9]{3}.*", incorrect: true, vulnerable: true } # 1.0.211
- { name: openstack-cinder, verpat: "201[24].*", sink: true }
- { name: openstack-glance, verpat: "201[24].*", sink: true }
- { name: openstack-heat, verpat: "201[24].*", sink: true }
- { name: openstack-horizon, verpat: "201[24].*", sink: true }
- { name: openstack-keystone, verpat: "201[24].*", sink: true }
- { name: openstack-neutron, verpat: "201[24].*", sink: true }
- { name: openstack-nova, verpat: "201[24].*", sink: true }
- { name: opentracker, noscheme: true }
- { name: opentyrian, ruleset: os4depot, incorrect: true }
- { name: opentyrian, ver: "2.1.20201204", ruleset: openbsd, incorrect: true }
- { name: opentyrian, ruleset: openbsd, untrusted: true } # accused of fake 2.1.20201204
- { name: opentyrian, ver: "2.1.20201203", ruleset: opensuse, incorrect: true }
- { name: opentyrian, ruleset: opensuse, untrusted: true } # accused of fake 2.1.20201203
- { name: openuniverse, ver: "1.0beta3.1", incorrect: true } # debian garbage
- { name: openvas, verpat: "20[0-9]{2}.*", incorrect: true } # blackarch
- { name: openvpn, verpat: ".*\\.[0-9]{3}", incorrect: true }
- { name: openvpn, ruleset: winget, untrusted: true } # accused of fake 2.5.020, 2.5.021
- { name: openvpn3, relge: "18", incorrect: true } # openvpn3-linux, not openvpn3
- { name: openvsp, verpat: "20[0-9]{6}", incorrect: true }
- { name: openxcom, verpat: ".*20[0-9]{2}.*", snapshot: true } # git snapshots
- { name: openxcom, verpat: ".*[0-9]{10}.*", incorrect: true } # opensuse games, totally braindead
- { name: openxcom, verpat: "[0-9a-f]+", incorrect: true } # pclos
- { name: openxcom, verpat: "20[0-9]{2}.*", incorrect: true }
- { name: openzfs, verpat: "20[0-9]{6}", incorrect: true }
- { name: orbit2, ver: "2.14.20", ruleset: sisyphus, incorrect: true } # alt fake
- { name: orbit2, ruleset: sisyphus, untrusted: true } # accused of fake 2.14.20
- { name: orc, ver: "0.4.30.1", ruleset: sisyphus, incorrect: true }
- { name: orc, ruleset: sisyphus, untrusted: true } # accused of fake 0.4.30.1
- { name: orthorobot, verlonger: 3, ruleset: freebsd, incorrect: true }
- { name: orthorobot, ruleset: freebsd, untrusted: true } # accused of fake 1.1.1.1
- { name: osc, verpat: ".*b.*", devel: true }
- { name: osdlyrics, verpat: "20[0-9]{2}.*", incorrect: true } # aosc
- { name: osinfo-db, ruleset: sisyphus, untrusted: true } # accused of fake 20201107
- { name: osinfo-db, ver: "20210105", ruleset: alpine, incorrect: true }
- { name: osinfo-db, ruleset: alpine, untrusted: true } # accused of fake 20210105
- { name: osm-gps-map, verpat: "r.*", snapshot: true }
- { name: osmosis, ver: "0.49.0", setver: "0.49.1", disposable: true } # build system fix which does not affect release
- { name: osquery, ver: "3.0.0", devel: true }
- { name: osu, ver: "2024.911.0", ruleset: aosc, incorrect: true }
- { name: osu, ruleset: aosc, untrusted: true } # accused of fake 2024.911.0
- { name: osu, verpat: "20[0-9]{6}.*", incorrect: true }
- { name: otrs, verge: "7", ignore: true } # no community releases after 6.x
- { name: otter-browser, ver: "1.1.0", ruleset: rosa, incorrect: true }
- { name: otter-browser, ruleset: rosa, untrusted: true } # accused of fake 1.1.0
- { name: otter-browser, ver: "1.0.01.1", ruleset: freebsd, incorrect: true } # fake
- { name: otter-browser, ruleset: freebsd, untrusted: true } # accused of fake 1.1.01.1
- { name: otter-browser, verpat: "[0-9]+\\.[0-9]+\\.[89][0-9]+", devel: true } # assumed https://sourceforge.net/projects/otter-browser/files/otter-browser-weekly360/
- { name: ovmf, noscheme: true }
- { name: owamp, ruleset: sisyphus, untrusted: true } # accused of fake 3.5.0
- { name: owfs, p_is_patch: true }
- { name: owncloudclient, verpat: ".*[0-9]{5}", snapshot: true } # openbsd
- { name: oxygen-gtk3, verlonger: 3, ruleset: kaos, incorrect: true }