-
Notifications
You must be signed in to change notification settings - Fork 609
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Add published field in output #2489
Comments
The upcoming grype-db schema v6 will add these fields: Lines 161 to 167 in 5dc2d2e
So this work is now unblocked. After v6 is adopted, changes will be needed in anchore/vunnel and anchore/grype-db to ensure the field is populated. I'm marking this as ready, since it's able to be worked on today. When someone starts working on a particular Vunnel provider, please open an issue to in Vunnel for that provider and link it here. |
Nice! Could you provide us with documentation about the schema, including version 6 and older ones? Having access to proper documentation would help us accurately interpret the return values of Grype. Without this, every user is left to decipher Grype’s output on their own, which can lead to inconsistencies, misunderstandings, and potential misinterpretations of vulnerabilities. In a cybersecurity-focused application like Grype, where precision and clarity are crucial, the absence of structured schema documentation can hinder effective usage. Providing official documentation would not only enhance user experience but also ensure that security professionals can rely on Grype’s output without ambiguity. Would it be possible to make this available? |
What would you like to be added?
It would be great and helpful to include the discovery date of vulnerabilities in the JSON output from Grype.
Why is this needed?
This feature is needed because some users may require information about when a vulnerability was first discovered. Knowing the discovery date can help in:
The text was updated successfully, but these errors were encountered: