10000 Security scans · Issue #2603 · anchore/grype · GitHub
[go: up one dir, main page]
More Web Proxy on the site http://driver.im/
Skip to content

Security scans #2603

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Closed
JL-Tests opened this issue Apr 17, 2025 · 2 comments
Closed

Security scans #2603

JL-Tests opened this issue Apr 17, 2025 · 2 comments
Labels
changelog-ignore Don't in 8000 clude this issue in the release changelog

Comments

@JL-Tests
Copy link
JL-Tests commented Apr 17, 2025

Hi grype Team,

FYI security scans with semgrep (image capture and csv attached) and gosec (Html report zipped and attached).
........ [REDACTED]
JL

@spiffcs
Copy link
Contributor
spiffcs commented Apr 17, 2025

👋 Hi @JL-Tests would you be able to sent these over via https://github.com/anchore/grype/blob/main/SECURITY.md#reporting-a-vulnerability

I've redacted and downloaded the report for now but we encourage responsible disclosure in this case 😄

@joshbressers
Copy link
Contributor

I'm going to close this. These are hardening measures that we may want to do someday, but this issue is not where it will happen. Running tools and dumping the results into an issue is irresponsible and annoying. This was not reported to the address @spiffcs asked them to send this data to.

We would love to see some PRs opened to resolve these issues.

@github-project-automation github-project-automation bot moved this to Done in OSS May 12, 2025
@wagoodman wagoodman added the changelog-ignore Don't include this issue in the release changelog label May 14, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
changelog-ignore Don't include this issue in the release changelog
Projects
Status: Done
Development

No branches or pull requests

4 participants
0