Uploaded image for project: 'Red Hat Advanced Cluster Security'
  1. Red Hat Advanced Cluster Security
  2. ROX-22663

Scanner V4 consider opening up communication with Maven Search

    • Icon: Task Task
    • Resolution: Done
    • Icon: Minor Minor
    • 4.8.0
    • None
    • None
    • None
    • Future Sustainability
    • False
    • Hide

      None

      Show
      None
    • False
    • Yes
    • 0

      ClairCore has the ability to search Maven for packages to get the groupID, artifactID, and version. We disable this to reduce network activity, but this means we may potentially miss vulnerabilities due to a potential lack of groupID from a pretty lacking MANIFEST.MF file.

      We should consider opening up this network traffic and/or making this configurable.

      Another option is for us to add the search results to a bundle. Take a look at https://github.com/aquasecurity/trivy-java-db for inspiration

              rh-ee-blugo Brad Lugo
              rtannenb@redhat.com Ross Tannenbaum
              ACS Scanner
              Votes:
              0 Vote for this issue
              Watchers:
              2 Start watching this issue

                Created:
                Updated:
                Resolved: