conflicting security reports with other SCA tools
Nobody has claimed this yet.
- Dominant language
- Shell
- Stars
- 454
- Forks
- 134
- PR merge metrics
- No merged PRs in 30d
Description
Docker Scout often presents more, or fewer CVE's compared with other SCA tools. For example, Docker Scout and Snyk Container tend to disagree on which CVE's apply to various images. Sometimes Docker Scout shows more CVE's. Sometimes Snyk Container shows more CVE's.
Can we please improve the CVE data for Docker Scout so that it behaves as a superset of the Snyk Database?
Contributor guide
No contributing guide indexed for this repository
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
The issue provides no repository file, test, or entry point; it only identifies Docker Scout, Snyk Container, and their CVE databases. Start by locating where Docker Scout sources and compares vulnerability data, then compare its results with the Snyk database and define completion as consistent coverage of the relevant Snyk CVEs.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- docker
- Domain
- security
- Issue type
- Bug
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 25/100