Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Different results between scan-action and grype run locally #239

Closed
jacopolanzonidev opened this issue Aug 16, 2023 · 2 comments
Closed
Labels
question Further information is requested

Comments

@jacopolanzonidev
Copy link

jacopolanzonidev commented Aug 16, 2023

My company uses Grype wrapped by your scan-action to detect vulnerabilities.

We currently observe a difference between what the scan-action's Grype finds as a GitHub Action and what we get by running Grype locally (installed through brew).

The version of Grype is the same (v0.63.0)

scan-action:

Screenshot 2023-08-16 at 17 01 36

Grype locally:

Screenshot 2023-08-16 at 17 04 30

@jacopolanzonidev jacopolanzonidev changed the title Vulnerabilities not found Different results between scan-action and grype run locally Aug 16, 2023
@jacopolanzonidev
Copy link
Author

Solution found. In my action I wasn't building the project into a jar file, and not all the vulnerabilities are found in that way.

@tgerla
Copy link

tgerla commented Aug 16, 2023

Thanks for letting us know!

@tgerla tgerla added the question Further information is requested label Aug 16, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
question Further information is requested
Projects
None yet
Development

No branches or pull requests

2 participants