Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Include vulnerability feed parsing code (maybe in another repo) #1115

Closed
rhdesmond opened this issue Feb 3, 2023 · 3 comments
Closed

Include vulnerability feed parsing code (maybe in another repo) #1115

rhdesmond opened this issue Feb 3, 2023 · 3 comments
Assignees
Labels
changelog-ignore Don't include this issue in the release changelog enhancement New feature or request

Comments

@rhdesmond
Copy link

rhdesmond commented Feb 3, 2023

What would you like to be added: The logic used for parsing the vulnerability feeds

Why is this needed:

Provides more transparency into the vulnerability data sources and creation of the vulnerability database (similar to open source scanners Trivy and osv-scanner).

@rhdesmond rhdesmond added the enhancement New feature or request label Feb 3, 2023
@tgerla
Copy link
Contributor

tgerla commented Feb 3, 2023

Hi @rhdesmond, this is something we're actively working on and we'll have something to share soon. It's a priority for us. Thanks for asking, and stay tuned. I'll leave this issue open and try to reply once we have something available.

@tgerla tgerla self-assigned this Feb 3, 2023
@rhdesmond
Copy link
Author

Awesome thanks! No rush

@wagoodman
Copy link
Contributor

Wanted to drop an update here: we've open sourced the entire data pipeline for grype-db! There are two projects that relate to this:

Here's the announcement post as well with further information https://anchore.com/blog/build-your-own-grype-database/

Shout out if you have more questions about this!

@wagoodman wagoodman added the changelog-ignore Don't include this issue in the release changelog label Sep 18, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
changelog-ignore Don't include this issue in the release changelog enhancement New feature or request
Projects
Archived in project
Development

No branches or pull requests

3 participants