pnoltes commented on issue #825:
URL: https://github.com/apache/celix/issues/825#issuecomment-5983972562

   @Adarsh-Me: There is some discussion going on with #845, but if that PR goes 
through, I agree it would be the logical starting point.
   
   I did not realize SARIF could also be used for dependency vulnerability 
findings. My understanding was that SARIF is mainly associated with SAST/code 
analysis, but apparently Trivy supports SARIF output (`--format sarif`). I am 
not sure how well this works in practice, but I think it is worth testing.
   
   I had a quick search on GitHub, but could not yet find a working example 
that uploads a Trivy-generated SARIF file. If anybody knows one, I would 
appreciate a link.
   
   For VEX, I am also not sure yet which format would be best (CycloneDX VEX or 
OpenVEX), or where we should store it. Keeping it in Git seems reasonable, but 
then we should think about how VEX information on main relates to already 
released Celix versions.
   
   If needed, work on this issue can already start using a dummy CycloneDX SBOM 
as input. Once #845 is merged, that dummy input can be removed.


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to