mirror of
https://github.com/anchore/grype
synced 2024-11-14 00:07:08 +00:00
25762b7e3b
* feat: disable CPE-based matching for GHSA ecosystems by default Disables CPE-based matching for ecosystems which are covered by GitHub Security Advisories. Also adds a separate rust matcher and related configuration to allow configuring CPE-based matching off for it while still leaving it on for the stock matcher. Signed-off-by: Weston Steimel <weston.steimel@anchore.com> * chore: use --by-cve with quality gate comparison Signed-off-by: Weston Steimel <weston.steimel@anchore.com> * chore: add rust auditable binary match integration test Signed-off-by: Weston Steimel <weston.steimel@anchore.com> --------- Signed-off-by: Weston Steimel <weston.steimel@anchore.com> |
||
---|---|---|
.. | ||
codeql-analysis.yml | ||
oss-project-board-add.yaml | ||
release.yaml | ||
scorecards.yml | ||
update-bootstrap-tools.yml | ||
update-syft-release.yml | ||
validations.yaml |