Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

indicate/filter out wontfix matches from results #74

Closed
wagoodman opened this issue Jul 27, 2020 · 5 comments
Closed

indicate/filter out wontfix matches from results #74

wagoodman opened this issue Jul 27, 2020 · 5 comments
Labels
changelog-ignore Don't include this issue in the release changelog I/O Describes bug or enhancement around application input or output

Comments

@wagoodman
Copy link
Contributor

Either filter or annotate wont-fix matches

@alfredodeza
Copy link
Contributor

@wagoodman where does the information about a wontfix show? Looking in different spots and I can't find any good places to look

@wagoodman
Copy link
Contributor Author

I haven't looked closely yet either. Today anchore-engine is doing this kind of filtering, so that could be a place to start. A guess would be that its data from the upstream vulnerability feed data for each linux distribution, either as an explicit field (which I don't recall existing) or derived from a field (such as severity).

@zhill
Copy link
Member

zhill commented Aug 14, 2020

We should enable a filter, but not have it done by default. We should default to showing everything.

@wagoodman wagoodman added the I/O Describes bug or enhancement around application input or output label Aug 23, 2021
@luhring
Copy link
Contributor

luhring commented May 31, 2022

@wagoodman Checking with you before taking action — but I'm thinking we might be able to close this now, since we can use our "ignore" functionality to filter by fix state now (https://github.com/anchore/grype#specifying-matches-to-ignore)

@wagoodman
Copy link
Contributor Author

Oh yeah, this is an oldie goldie

@wagoodman wagoodman added the changelog-ignore Don't include this issue in the release changelog label Jun 1, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
changelog-ignore Don't include this issue in the release changelog I/O Describes bug or enhancement around application input or output
Projects
None yet
Development

No branches or pull requests

4 participants