ossf/scorecard vulnerabilities fix tracking issue
- Dominant language
- Go
- Stars
- 9.6k
- Forks
- 954
- Avg merge
- 1d 5h
- Merged PRs (30d)
- 42
Description
**What would you like to be added**:
We recently ran the `ossf/scorecard`[^1] over the `Syft` project, found some vulnerabilities, here is the output of the scan:
```shell
$ docker run -e GITHUB_AUTH_TOKEN=$GITHUB_TOKEN gcr.io/openssf/scorecard:stable --repo https://github.com/developer-guy/syft
```


**Why is this needed**:
To make `Syft` more secure.
**Additional context**:
[^1]: https://github.com/ossf/scorecard
cc: @wagoodman @luhring @dentrax
Contributor guide
Research direction
Start by running the documented ossf/scorecard Docker command against the Syft repository and review the scan output shown in the issue. Use the reported vulnerabilities to identify the affected areas; done means the findings are addressed and a follow-up scan no longer reports them.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- docker, go
- Domain
- cli, security
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 20/100