You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
An observation when reviewing the grype plugin was that it is able to output Package URLs for detected packages that have CVEs -- since grype is based on Syft for package recognition, Syft should be able to output Package URLs for all packages detected regardless of if they have CVEs or not. This would be useful information to include in our SBOMs.
Eventually we should add a hook that lets plugins run on entire directories if they want, rather than just a single file at a time -- I think the Syft plugin and several other tools would benefit from this (should probably make this its own issue to track it). And maybe a separate issue to discuss the unifying the output formats from the cvebin2vex and grype plugins.
The text was updated successfully, but these errors were encountered:
An observation when reviewing the grype plugin was that it is able to output Package URLs for detected packages that have CVEs -- since grype is based on Syft for package recognition, Syft should be able to output Package URLs for all packages detected regardless of if they have CVEs or not. This would be useful information to include in our SBOMs.
Eventually we should add a hook that lets plugins run on entire directories if they want, rather than just a single file at a time -- I think the Syft plugin and several other tools would benefit from this (should probably make this its own issue to track it). And maybe a separate issue to discuss the unifying the output formats from the cvebin2vex and grype plugins.
The text was updated successfully, but these errors were encountered: