Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Exclude options #547

Open
kzantow opened this issue Oct 12, 2021 · 3 comments
Open

Exclude options #547

kzantow opened this issue Oct 12, 2021 · 3 comments
Labels
enhancement New feature or request

Comments

@kzantow
Copy link
Contributor

kzantow commented Oct 12, 2021

What would you like to be added:
Ability to exclude items from the reports -- quite possibly ported and/or moved from the Grype excludes.

Why is this needed:
Some projects include only a small portion of a library that may be reported as vulnerable. It is not accurate to report these as "included".

Additional context:
Talking with the containerd folks, there are some packages which could result in false positive vulnerability scans, or even somewhat falsely reported as included because they are only using one package out of many, it would be very useful to prescriptively exclude certain results: https://cloud-native.slack.com/archives/CGEQHPYF4/p1634051863179900?thread_ts=1633986885.169500&cid=CGEQHPYF4

@kzantow kzantow added the enhancement New feature or request label Oct 12, 2021
@luhring
Copy link
Contributor

luhring commented Oct 18, 2021

We should figure out a way to disambiguate "exclude" as a coined term within Syft and Grype. We're also using "exclude" to refer to a slightly different functionality from Grype's ignore rules, referring instead to omitting certain file paths from Syft/Grype's scan in the first place. See #221

@wagoodman
Copy link
Contributor

@kzantow is this a dup of #221 ?

@kzantow
Copy link
Contributor Author

kzantow commented Dec 20, 2021

@wagoodman this is not exactly the same thing, no

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New feature or request
Projects
Status: No status
Development

No branches or pull requests

3 participants