cve-bin-tool icon indicating copy to clipboard operation
cve-bin-tool copied to clipboard

Improve behaviour for -i when specified file is binary

Open terriko opened this issue 1 year ago • 0 comments

When you specify a bill of materials/csv/json file where cve-bin-tool is expecting a binary, we have code that makes it "do the right thing" and switch to -i to attempt to read the bill of materials.

We currently don't do this the other way: if you specify -i filename and the filename is a binary file, it doesn't output a warning message and goes ahead and reports 0 CVEs found. This isn't great, since it could lead people to believe that something is safe when it's not, it's just not being scanned correctly.

Thanks to @nedsouza for pointing this out.

terriko avatar Aug 03 '22 16:08 terriko