-
Notifications
You must be signed in to change notification settings - Fork 574
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
grype scan by sbom file is generated by syft different with scanning directly container #1057
Comments
I suspect we're losing the file overlap relationships in CycloneDX format. As a workaround, you could use a Syft format SBOM (e.g. using |
|
@kzantow Does this mean there is an issue with the JSON output format? |
Apologies for the delay getting back here -- I don't think this is an issue with CycloneDX in Grype, it's an issue that CycloneDX doesn't support certain types of relationships, so outputting a Syft SBOM in CycloneDX is lossy and can lead to worse results in Grype. There isn't a specific thing we can do to fix this until CycloneDX supports at least |
grype scan by sbom file is generated by syft different with scanning directly container
grype scan sbom file and directly ccontainer should be same
Environment:
grype version
: 0.55.0cat /etc/os-release
or similar):The text was updated successfully, but these errors were encountered: