anchore / anchore/syft

Enhance CPE generation for packaged JVMs

Open
#3,271 0 comments 0 reactions 0 assignees View on GitHub
ecosystem:java enhancement
Dominant language
Go
Stars
9.6k
Forks
954
Avg merge
1d 5h
Merged PRs (30d)
42

Description

**What would you like to be added**:
The ability to enrich already packaged JVMs with similar information that the JVM cataloger is now raising up (from the jdk release file). At the very least this information should influence the generated CPEs, pURLs, and name/version identification when possible, even if all of the information is not captured as metadata.

**Why is this needed**:
Based on https://github.com/anchore/syft/issues/2422#issuecomment-1914722062 and https://github.com/anchore/syft/issues/2422#issuecomment-2371460117 , though #3217 added the ability to catalog JVMs with more nuanced information, this was isolated to unpackaged JVMs.

Contributor guide

Open the contributing guide

Research direction

The issue names packaged JVMs, the JVM cataloger, the JDK release file, and comparison issue #3217; start by tracing how packaged JVMs are handled alongside the cataloger behavior added there. Done means available release information influences generated CPEs, pURLs, and name/version identification for packaged JVMs when possible.

Written by the indexing model from the issue text.

Assessment

Tech stack
go
Domain
cli, devtools
Issue type
Feature
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.