anchore / anchore/vulnerability-match-labels

Images we should add some labels for

Open
#2 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
Python
Stars
14
Forks
12
Avg merge
15h 56m
Merged PRs (30d)
1

Description

Also ensure we add in the true positives that grype misses. One good example for python is https://github.com/anchore/grype/issues/940

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start with the repository's existing labeled vulnerability-package match data and the checklist in this issue, noting that Python and nodejs are already checked. Review the linked Grype issues 942 and 940 to identify additional image labels and true positives that Grype misses; done means the requested ecosystems and confirmed true positives are represented in the dataset.

Written by the indexing model from the issue text.

Assessment

Tech stack
go, nodejs, php, python, ruby, rust, wordpress
Domain
data, security
Issue type
Feature
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.