Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add Can ecosystem and GITLAB Advisory database #1827

Open
jacky92 opened this issue Apr 25, 2024 · 1 comment
Open

Add Can ecosystem and GITLAB Advisory database #1827

jacky92 opened this issue Apr 25, 2024 · 1 comment
Labels
enhancement New feature or request

Comments

@jacky92
Copy link

jacky92 commented Apr 25, 2024

Hello,

What would you like to be added:
I would like to add Conan (C/C++ package manager) CVEs on Grype

Why is this needed:
Syft support Conan scanning.
GITLAB Advisory database manage conan CVE.

Additional context:
URL to GITLAB Advisory : https://gitlab.com/gitlab-org/advisories-community
GITLAB Advisory support also GEM/GO/MAVEN/NPM/NUGET/PYPI, maybe it is possible to add complementary information for these ecosystem...

Thanks in advance.

@jacky92 jacky92 added the enhancement New feature or request label Apr 25, 2024
@tgerla
Copy link
Contributor

tgerla commented Apr 25, 2024

Hey @jacky92, thank you for the request. This is probably something we could do by implementing a new provider in https://github.com/anchore/vunnel to parse the publicly-available GitLab data. Note: if we implemented that, we'd need to also implement a per-ecosystem filter to prevent duplicates of vulnerabilities from GHSA that we would also be using to match in Grype. If you are interested in working on the Vunnel provider, please let us know! We would be happy to help get you pointed in the right direction.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New feature or request
Projects
Status: Backlog
Development

No branches or pull requests

2 participants