anchore / anchore/syft

ossf/scorecard vulnerabilities fix tracking issue

Open
#593 3 comments 1 reaction 0 assignees View on GitHub
enhancement
Dominant language
Go
Stars
9.6k
Forks
954
Avg merge
1d 5h
Merged PRs (30d)
42

Description

**What would you like to be added**:

We recently ran the `ossf/scorecard`[^1] over the `Syft` project, found some vulnerabilities, here is the output of the scan:

```shell
$ docker run -e GITHUB_AUTH_TOKEN=$GITHUB_TOKEN gcr.io/openssf/scorecard:stable --repo https://github.com/developer-guy/syft
```

![Screen Shot 2021-10-26 at 16 12 12](https://user-images.githubusercontent.com/16693043/138886029-739919c4-f8b0-4c24-b5b1-edeaa0110d79.png)
![Screen Shot 2021-10-26 at 16 11 56](https://user-images.githubusercontent.com/16693043/138886034-b820c419-5f82-4d49-9e65-af57a3de6662.png)

**Why is this needed**:

To make `Syft` more secure.

**Additional context**:

[^1]: https://github.com/ossf/scorecard

cc: @wagoodman @luhring @dentrax

Contributor guide

Open the contributing guide

Research direction

Start by running the documented ossf/scorecard Docker command against the Syft repository and review the scan output shown in the issue. Use the reported vulnerabilities to identify the affected areas; done means the findings are addressed and a follow-up scan no longer reports them.

Written by the indexing model from the issue text.

Assessment

Tech stack
docker, go
Domain
cli, security
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
20/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.