Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Support PURL in OpenVEX #4765

Closed
knqyf263 opened this issue Jul 3, 2023 · 0 comments · Fixed by #5061
Closed

Support PURL in OpenVEX #4765

knqyf263 opened this issue Jul 3, 2023 · 0 comments · Fixed by #5061
Labels
kind/feature Categorizes issue or PR as related to a new feature. scan/vulnerability Issues relating to vulnerability scanning
Milestone

Comments

@knqyf263
Copy link
Collaborator

knqyf263 commented Jul 3, 2023

Description

Currently, Trivy supports filtering detected vulnerabilities using the Vulnerability Exploitability Exchange (VEX), with support for the OpenVEX format. This feature is in its experimental phase and has only minimal functionality added ​1​.

While using Package URLs (PURLs) for comparison was initially avoided due to ambiguities in the comparison methodology, there is an ongoing discussion in the OpenVEX community that presents potential solutions to these issues​ 2​.

Given this ongoing conversation and the potential clarity it can bring to PURL comparison, I propose that we explore the experimental implementation of PURL comparison within Trivy's OpenVEX support.

This issue is intended to start a conversation around this idea, and to explore potential paths for implementation. All thoughts, comments, and suggestions are welcome as we explore this possibility.

@knqyf263 knqyf263 added kind/feature Categorizes issue or PR as related to a new feature. scan/vulnerability Issues relating to vulnerability scanning labels Jul 3, 2023
@knqyf263 knqyf263 added this to the v0.44.0 milestone Jul 3, 2023
@knqyf263 knqyf263 modified the milestones: v0.44.0, v0.45.0 Jul 30, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
kind/feature Categorizes issue or PR as related to a new feature. scan/vulnerability Issues relating to vulnerability scanning
Projects
Archived in project
Development

Successfully merging a pull request may close this issue.

1 participant