-
Outcome
-
Resolution: Unresolved
-
Normal
-
None
-
None
-
None
-
False
-
Inspired by another discussion, it seems like we may not have a way to discover the repository a java package is installed from.
We currently assume everything is installed from Maven central, which is not correct but good enough if we're only considering public/OSV data. If Red Hat starts producing VEX data for Java packages, we'll need to be able to identify which packages come from a Red Hat repository.
- clones
-
CLAIRDEV-215 claircore: python: can index information be discovered?
-
- Closed
-
- relates to
-
CLAIRDEV-217 claircore: Red Hat middleware support
-
- Refinement
-