Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Revisit information available from Syft #232

Open
nightlark opened this issue Jul 23, 2024 · 0 comments
Open

Revisit information available from Syft #232

nightlark opened this issue Jul 23, 2024 · 0 comments
Labels
enhancement New feature or request

Comments

@nightlark
Copy link
Collaborator

An observation when reviewing the grype plugin was that it is able to output Package URLs for detected packages that have CVEs -- since grype is based on Syft for package recognition, Syft should be able to output Package URLs for all packages detected regardless of if they have CVEs or not. This would be useful information to include in our SBOMs.

Eventually we should add a hook that lets plugins run on entire directories if they want, rather than just a single file at a time -- I think the Syft plugin and several other tools would benefit from this (should probably make this its own issue to track it). And maybe a separate issue to discuss the unifying the output formats from the cvebin2vex and grype plugins.

@nightlark nightlark added the enhancement New feature or request label Jul 23, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New feature or request
Projects
None yet
Development

No branches or pull requests

1 participant