Uploaded image for project: 'Clair'
  1. Clair
  2. CLAIRDEV-132

Reduce false positives due to APK

XMLWordPrintable

    • Icon: Task Task
    • Resolution: Unresolved
    • Icon: Minor Minor
    • None
    • None
    • indexer
    • None
    • False
    • Hide

      None

      Show
      None
    • False

      Similar to https://issues.redhat.com/browse/CLAIRDEV-10, APKs may install language package like Go and Node.js, too.

      Chainguard specifically calls this out in its scanner implementation guide (https://github.com/chainguard-dev/vulnerability-scanner-support/blob/main/docs/scanning_implementation.md#discovering-non-distro-packages-for-vulnerability-matching), so we should be sure to account for this so we may add Chainguard and Wolfi support

              Unassigned Unassigned
              rtannenb@redhat.com Ross Tannenbaum
              Votes:
              0 Vote for this issue
              Watchers:
              1 Start watching this issue

                Created:
                Updated: