anchore / anchore/yardstick

Support tools that are both SBOM generators and vulnerability scanners

Open
#10 0 comments 0 reactions 0 assignees View on GitHub
enhancement
Dominant language
Python
Stars
27
Forks
9
Avg merge
2m
Merged PRs (30d)
5

Description

**What would you like to be added**:

Support for tools that are both SBOM generators and vulnerability scanners. Currently we could work around this by adding two unique entries for the tool, and this may be the easiest path forward for now, but would be nice to discuss if there is some design enhancement we can make for a single tool to support both.

Contributor guide

Open the contributing guide

Research direction

Review how tool entries are currently represented and how the two-entry workaround is handled; the issue does not identify files or tests. Define the design for representing one tool as both an SBOM generator and vulnerability scanner, then verify that existing tools continue to work and the new representation is covered by tests.

Written by the indexing model from the issue text.

Assessment

Tech stack
python
Domain
security, tooling
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
30/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.