10000 fix: indicate upstream packages for sbom cataloger by VictorHuu · Pull Request #3849 · anchore/syft · GitHub
[go: up one dir, main page]
More Web Proxy on the site http://driver.im/
Skip to content

fix: indicate upstream packages for sbom cataloger #3849

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

< 8000 /details>
Open
wants to merge 2 commits into
base: main
Choose a base branch
from

Conversation

VictorHuu
Copy link
Contributor
@VictorHuu VictorHuu commented May 4, 2025

Description

To include the GENERATED_FROM relationships is a good way to resolve the issue, (but there might be better solutions to it,or maybe it's up to Grype not to make the upstream package false positive)

Proposal: we can preserve the name&version pair of the upstream packages in the comment field of the relationship like evidence/ownership-by-file-overlap or and strip the upstream packages out.

This proposal will introduce huge amounts of updates ,so the first option is preferred. Keep the packages as they were.

Type of change

  • Bug fix (non-breaking change which fixes an issue)

Checklist:

  • I have added unit tests that cover changed behavior
  • I have tested my code in common scenarios and confirmed there are no regressions
  • I have added comments to my code, particularly in hard-to-understand sections

Signed-off-by: Yuntao Hu <victorhu493@gmail.com>
@VictorHuu VictorHuu marked this pull request as ready for review May 6, 2025 13:16
@VictorHuu VictorHuu marked this pull request as draft May 11, 2025 12:08
Signed-off-by: Yuntao Hu <victorhu493@gmail.com>
@VictorHuu VictorHuu marked this pull request as ready for review May 14, 2025 16:40
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

sbom cataloger returning upstream package
1 participant
0