-
Notifications
You must be signed in to change notification settings - Fork 583
Issues: anchore/grype
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Author
Label
Projects
Milestones
Assignee
Sort
Issues list
False positive: GHSA-6vqw-3v5j-54x4_CVE-2024-26130 python311-cryptography with SLES 15.5 and SLES 15.6 due to noise from Syft
bug
Something isn't working
#2342
opened Dec 18, 2024 by
sekveaja
Question: Custom Vulnerability Sources CSAF
enhancement
New feature or request
#2337
opened Dec 17, 2024 by
jurassicLizard
possible false positives: unicorn package, qnx SDK package
bug
Something isn't working
#2336
opened Dec 17, 2024 by
jurassicLizard
False negative: vulns in AL2023 rpm packages were reported but then disappeared
bug
Something isn't working
#2333
opened Dec 16, 2024 by
sparrowt
FP in upstream of a package that doesn't exist
bug
Something isn't working
#2327
opened Dec 12, 2024 by
tomersein
Add support for Wind River Linux
enhancement
New feature or request
#2325
opened Dec 12, 2024 by
joshbressers
[DOCS] Document your CycloneDX properties
documentation
Improvements or additions to documentation
enhancement
New feature or request
needs-discussion
#2316
opened Dec 11, 2024 by
jkowalleck
False positive: GHSA-jjg7-2v4v-x38h (CVE-2024-3651) in SLES 15.6 and 15.5 Ecosystem cause by Syft noise with extra reference
bug
Something isn't working
#2314
opened Dec 10, 2024 by
sekveaja
Automatically determine the current debian sid codename
enhancement
New feature or request
#2302
opened Dec 4, 2024 by
wagoodman
False positive on a custom image with custom python package
bug
Something isn't working
#2292
opened Dec 1, 2024 by
tony-oss-titan
False Positive: GHSA-gf2q-j2qq-pjf2(CVE-2012-3542) GHSA-mrxv-65rv-6hxq (CVE-2012-4413) keystone 18.x.x, recommend fixed with 2012.x older versioning convention
bug
Something isn't working
epoch
relating to issues around version lineage changes
false-positive
#2289
opened Nov 27, 2024 by
sekveaja
Grype DB schemas v3 & v4 deprecation notice
deprecation
related to features that will be removed from grype
#2286
opened Nov 26, 2024 by
wagoodman
list of unrelated versions in the remediation
bug
Something isn't working
needs-discussion
#2264
opened Nov 17, 2024 by
TimBrown1611
Failure on SBOM from cdxgen 11.0.0
bug
Something isn't working
#2263
opened Nov 16, 2024 by
metametadata
False positive:GHSA-wf44-4mgj-rwvx( CVE-2015-3221) neutron 17.x.x, recommend fixed with 2014.x older versioning convention
bug
Something isn't working
epoch
relating to issues around version lineage changes
needs-investigation
#2262
opened Nov 15, 2024 by
sekveaja
Incorrect cve fixed-in version coming in grype output
bug
Something isn't working
needs-discussion
#2253
opened Nov 12, 2024 by
nehas4
False positive:GHSA-q748-mcwg-xmqv(CVE-2015-5251), GHSA-gvjg-r9fv-7qx9(CVE-2015-5286) glance 21.x.x, recommend fixed with 2014.x older versioning convention
bug
Something isn't working
epoch
relating to issues around version lineage changes
false-positive
#2252
opened Nov 11, 2024 by
sekveaja
False positive: GHSA-qhch-g8qr-p497 (CVE-2014-3641) cinder 17.4.1.x, recommend fixed with 2014.x older versioning convention.
bug
Something isn't working
epoch
relating to issues around version lineage changes
needs-investigation
#2240
opened Nov 5, 2024 by
sekveaja
Removal of temporary files not working on Windows
bug
Something isn't working
windows
related to the windows ecosystem
#2233
opened Nov 2, 2024 by
Joerki
some non-PEP440 version constraints for GHSA python packages in grype-db
bug
Something isn't working
needs-discussion
#2229
opened Oct 31, 2024 by
willmurphyscode
Feature request: Grype Convert
enhancement
New feature or request
#2224
opened Oct 30, 2024 by
tidusete
POM data should be derived from pom.xml when available
bug
Something isn't working
#2217
opened Oct 28, 2024 by
wagoodman
Should only check maven central if pom info is missing
bug
Something isn't working
#2216
opened Oct 28, 2024 by
wagoodman
Previous Next
ProTip!
Find all open issues with in progress development work with linked:pr.