grype/test/integration
Weston Steimel 4cda526992
implement v5 db schema to support improved matching between rpm appstream modules (#944)
Adds support for a `package_qualifiers` column to allow evaluating package matches to vulnerabilities based on more than just version constraints. Currently adds an rpm-modularity qualifier in order to support matching to correct app stream module in order to reduce false positives within rpm-based distro ecosystems. In order to prevent an increase in false positive matches for previous versions of grype using the v4 schema, this change (along with the vulnerability source driver parser updates) requires bumping the schema to v5.

Signed-off-by: Weston Steimel <weston.steimel@anchore.com>
Signed-off-by: Alex Goodman <alex.goodman@anchore.com>
Co-authored-by: Alex Goodman <alex.goodman@anchore.com>
2022-10-18 00:34:47 +01:00
..
test-fixtures implement v5 db schema to support improved matching between rpm appstream modules (#944) 2022-10-18 00:34:47 +01:00
compare_sbom_input_vs_lib_test.go update grype to use syft v0.52.0 (#838) 2022-07-22 16:12:18 +00:00
db_mock_test.go implement v5 db schema to support improved matching between rpm appstream modules (#944) 2022-10-18 00:34:47 +01:00
diff_test.go implement v5 db schema to support improved matching between rpm appstream modules (#944) 2022-10-18 00:34:47 +01:00
match_by_image_test.go Add support for scanning RPM files (#917) 2022-09-09 14:56:37 -04:00
match_by_sbom_document_test.go feat: extract use cpes in matching logic to be configurable (#911) 2022-09-06 09:55:35 -04:00
utils_test.go Update to Syft v0.41.4 (#664) 2022-03-14 17:15:09 -04:00