pnoltes commented on issue #825: URL: https://github.com/apache/celix/issues/825#issuecomment-5983972562
@Adarsh-Me: There is some discussion going on with #845, but if that PR goes through, I agree it would be the logical starting point. I did not realize SARIF could also be used for dependency vulnerability findings. My understanding was that SARIF is mainly associated with SAST/code analysis, but apparently Trivy supports SARIF output (`--format sarif`). I am not sure how well this works in practice, but I think it is worth testing. I had a quick search on GitHub, but could not yet find a working example that uploads a Trivy-generated SARIF file. If anybody knows one, I would appreciate a link. For VEX, I am also not sure yet which format would be best (CycloneDX VEX or OpenVEX), or where we should store it. Keeping it in Git seems reasonable, but then we should think about how VEX information on main relates to already released Celix versions. If needed, work on this issue can already start using a dummy CycloneDX SBOM as input. Once #845 is merged, that dummy input can be removed. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
