-
Task
-
Resolution: Unresolved
-
Undefined
-
None
-
None
-
None
-
None
Similar to RPMs, APKs may also install language packages (JavaScript, Go, etc). Chainguard explicitly calls these out and tells scanning vendors they need to eliminate these false-positives. See https://github.com/chainguard-dev/vulnerability-scanner-support/blob/main/docs/scanning_implementation.md#discovering-non-distro-packages-for-vulnerability-matching for more information.
This is also tracked in https://issues.redhat.com/browse/CLAIRDEV-132.
- is related to
-
CLAIRDEV-132 Reduce false positives due to APK
-
- Refinement
-