Uploaded image for project: 'Clair'
  1. Clair
  2. CLAIRDEV-228

Test hummingbird images can match to associated VEX advisories

XMLWordPrintable

    • Icon: Task Task
    • Resolution: Unresolved
    • Icon: Critical Critical
    • None
    • claircore-1.5.48
    • matcher
    • None

      We need to end to end test the RHCC matching logic for Hummingbird images to check the whole pipeline works as expected.

      Things to be aware of:

      • Basic labels.json file processing is working
      • VEX updater parsing Hummingbird OCI advisories correctly
      • False-positive mitigation is working (rpm provenance information being surfaced correctly).
      • TBD: the from_dnf_hint could be used to match RPMs but:
        • The repository in the content set would need to be in the repository_to_cpe map
        • The VEX advisories need to correctly surface that repository CPE.

              Unassigned Unassigned
              jcroslan@redhat.com Joseph Crosland
              Votes:
              0 Vote for this issue
              Watchers:
              3 Start watching this issue

                Created:
                Updated: