Enhance CPE generation for packaged JVMs
- Dominant language
- Go
- Stars
- 9.6k
- Forks
- 954
- Avg merge
- 1d 5h
- Merged PRs (30d)
- 42
Description
**What would you like to be added**:
The ability to enrich already packaged JVMs with similar information that the JVM cataloger is now raising up (from the jdk release file). At the very least this information should influence the generated CPEs, pURLs, and name/version identification when possible, even if all of the information is not captured as metadata.
**Why is this needed**:
Based on https://github.com/anchore/syft/issues/2422#issuecomment-1914722062 and https://github.com/anchore/syft/issues/2422#issuecomment-2371460117 , though #3217 added the ability to catalog JVMs with more nuanced information, this was isolated to unpackaged JVMs.
Contributor guide
Research direction
The issue names packaged JVMs, the JVM cataloger, the JDK release file, and comparison issue #3217; start by tracing how packaged JVMs are handled alongside the cataloger behavior added there. Done means available release information influences generated CPEs, pURLs, and name/version identification for packaged JVMs when possible.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- go
- Domain
- cli, devtools
- Issue type
- Feature
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 35/100