anchore / anchore/syft

Expose file metadata for image contents

Open
#477 3 comments 0 reactions 0 assignees View on GitHub
enhancement format:spdx I/O
Dominant language
Go
Stars
9.6k
Forks
954
Avg merge
1d 5h
Merged PRs (30d)
42

Description

Today the package catalogers expose some file information from the cataloging source, not directly about the file on disk (e.g. indirect file metadata from the RPM DB, not metadata gotten directly from the file location in the image archive). It would be interesting to expose out direct (not indirect) file metadata information as artifacts in at least the context of SPDX SBOM format.

This involves looking at the existing file cataloger and understanding if it should be invoked conditionally based on the user output format option, or directly by the presenter object (not ideal), or something else.

Contributor guide

Open the contributing guide

Research direction

Start by reading the existing file cataloger and the presenter/output-format handling described in the issue, with particular attention to SPDX SBOM generation. Determine where direct file metadata should enter the artifact model and define done as exposing that metadata in SPDX output without relying on indirect package-database information.

Written by the indexing model from the issue text.

Assessment

Tech stack
go
Domain
cli
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.