-
Epic
-
Resolution: Unresolved
-
Blocker
-
None
-
None
-
None
-
None
-
VEX issues that result in false reporting
-
False
-
-
False
-
In Progress
-
25% To Do, 0% In Progress, 75% Done
Certain issues with the VEX file formatting and accuracy of the data are leading to complaints from service owners who have clair or claircore as a dependency, this means that, most likely, all services dependent on clair or claircore are affected (although each issue is not verified as affecting each product).
Each SECDATA child issue should have an "Impact Statement" that describes the general effects of the issue, this epic is a way to group these issues and communicate with clair/claircore stakeholders.
Clair/Claircore dependent products / services:
- Quay / Quay.io
- ACS Scanner
- Container catalogue grading
- Konflux pipelines
- Fedramp reporting
- causes
-
PROJQUAY-9299 [3.15] Update downstream to use latest Clair version
-
- New
-
-
PROJQUAY-9300 [3.14] Update downstream to use latest Clair version
-
- New
-
- is caused by
-
SECDATA-1116 Missing Architecture in PURL for Affected RPM Package
-
- Closed
-
- links to