Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Find purl based on component name and sbom #994

Closed
dejanb opened this issue Nov 12, 2024 · 1 comment
Closed

Find purl based on component name and sbom #994

dejanb opened this issue Nov 12, 2024 · 1 comment
Assignees
Labels
UI-V1 parity Tasks needed to get done for V1 UI parity Vulnerability Correlation Correlation of vulnerabilities to Packages, SBOMs and Products

Comments

@dejanb
Copy link
Contributor

dejanb commented Nov 12, 2024

#948 is able to make vulnerability to sbom correlations (and back) based only on the component names mentioned in advisories. The next step is to use graph analysis to try and find purls for these component names in SBOMs and include them into the response

@JimFuller-RedHat JimFuller-RedHat self-assigned this Nov 18, 2024
@dejanb dejanb added Vulnerability Correlation Correlation of vulnerabilities to Packages, SBOMs and Products UI-V1 parity Tasks needed to get done for V1 UI parity labels Nov 20, 2024
@JimFuller-RedHat JimFuller-RedHat closed this as completed by moving to Done in Trustify Nov 21, 2024
@dejanb
Copy link
Contributor Author

dejanb commented Nov 22, 2024

This is still pedning based on #1014 completion.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
UI-V1 parity Tasks needed to get done for V1 UI parity Vulnerability Correlation Correlation of vulnerabilities to Packages, SBOMs and Products
Projects
Archived in project
Development

No branches or pull requests

2 participants