vulndb: move from package structured vulnerabilities to module

Adapts govulncheck to work with a database structured around per-module
vulnerabilities, rather than per-package vulnerabilities.

This requires a significant refactor of various aspects of the main
package and the internal/audit packages which, while large, I think
makes the overall program flow somewhat simpler to understand. Some
changes to tests are also required, although similarly I believe they
end up with easier to understand/modify tests.

This also paves the way for more comprehensive details around which
vulnerabilities are unreachable.

Change-Id: I3dd402db344849db6f1a118feee65734daf924cf
Trust: Roland Shoemaker <>
Run-TryBot: Roland Shoemaker <>
TryBot-Result: Go Bot <>
Reviewed-by: Zvonimir Pavlinovic <>
20 files changed
tree: 639580b83a8765d3522956fa375eb8b3811f30f8
  1. apidiff/
  2. cmd/
  3. ebnf/
  4. ebnflint/
  5. errors/
  6. event/
  7. fsnotify/
  8. inotify/
  9. internal/
  10. io/
  11. jsonrpc2/
  12. mmap/
  13. rand/
  14. shiny/
  15. shootout/
  16. sumdb/
  17. utf8string/
  18. vulndb/
  19. winfsnotify/
  20. .gitattributes
  21. .gitignore
  28. codereview.cfg
  29. go.mod
  30. go.sum



This subrepository holds experimental and deprecated (in the old directory) packages.

The idea for this subrepository originated as the pkg/exp directory of the main repository, but its presence there made it unavailable to users of the binary downloads of the Go installation. The subrepository has therefore been created to make it possible to go get these packages.

Warning: Packages here are experimental and unreliable. Some may one day be promoted to the main repository or other subrepository, or they may be modified arbitrarily or even disappear altogether.

In short, code in this subrepository is not subject to the Go 1 compatibility promise. (No subrepo is, but the promise is even more likely to be violated by go.exp than the others.)

Caveat emptor.