mirror of
https://github.com/anchore/grype
synced 2024-11-10 14:44:12 +00:00
7ff37a0310
For example, if the rpm "python3-rpm" is installed, it brings a python package called "rpm" with it, which is just python bindings to RPM. But this python package is part of "python3-rpm", and should not be matched against directly. Only apply this deduplication strategy on distros with a comprehensive enough vulnerability feed that we don't expect false negatives from it. Signed-off-by: Will Murphy <will.murphy@anchore.com> |
||
---|---|---|
.. | ||
test-fixtures | ||
compare_sbom_input_vs_lib_test.go | ||
db_mock_test.go | ||
diff_test.go | ||
match_by_image_test.go | ||
match_by_sbom_document_test.go | ||
utils_test.go |