-
Notifications
You must be signed in to change notification settings - Fork 10
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
How to match pkg/nix/* PURLs to Vulnerabilities? #135
Comments
There's no official PURL spec yet for Nix. However, there is a draft PR open: package-url/purl-spec#314 Not super clear to me, how to use this for vulnerability analysis. Happy to change the PURL if there is a good proposal. See also how syft creates Nix PURLS: anchore/syft#1696 |
Correct CPEs would help, but sbomnix generates wrong CPEs. For glibc it generates I'm not sure whether the CPEs can be autogenerated, but adding the relevant fields to the |
I'm not opposed to guessing, however, we could also guess PURLs as I don't see why CPEs would be better. Adding a CPE or PURL meta field seems like the even better solution though. It's probably worth it to coordinate with the security tracker team on this. |
@nikstur did you received any feedback from the security tracker team regarding PURL's or CPE's? |
Bombon generates Package URLs, such as these:
As far as I can see, there is no CVE data source for these PURLs. Is there any advice on how to handle these for vulnerability analysis?
The text was updated successfully, but these errors were encountered: