anchore / anchore/syft

Exclude options

Open
#547 3 comments 0 reactions 0 assignees View on GitHub
enhancement
Dominant language
Go
Stars
9.6k
Forks
962
Avg merge
23h 27m
Merged PRs (30d)
48

Description

**What would you like to be added**:
Ability to exclude items from the reports -- quite possibly ported and/or moved from the Grype excludes.

**Why is this needed**:
Some projects include only a small portion of a library that may be reported as vulnerable. It is not accurate to report these as "included".

**Additional context**:
Talking with the containerd folks, there are some packages which could result in false positive vulnerability scans, or even somewhat falsely reported as included because they are only using one package out of many, it would be very useful to prescriptively exclude certain results: https://cloud-native.slack.com/archives/CGEQHPYF4/p1634051863179900?thread_ts=1633986885.169500&cid=CGEQHPYF4

Contributor guide

Open the contributing guide

Research direction

The issue names reports and Grype excludes but no Syft files, tests, or entry point. Start by locating the report-generation path and comparing the requested behavior with Grype's exclusion model; done means users can prescriptively exclude selected results from reports.

Written by the indexing model from the issue text.

Assessment

Tech stack
go
Domain
cli, security
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.