Dan Luhring
Dan Luhring
We're expecting a forthcoming Grype release to resolve the test failure 🤞
Going to take a closer look at this now since we still haven't seen a Grype release
@dependabot rebase
The best option might be to update `CreateOptions` to allow the caller to override how CGA IDs are generated (and do the same for Update, too)
Curious if anyone has seen this happen recently 🤔
cc: @rawlingsj
Yeah @hectorj2f this isn't meant to be used yet 😄 still a draft PR — I just wanted to show the general idea and the progress toward that idea so...
Note: The team has decided not to pursue merging this PR. We'll leave it here for a short time to serve as a reference for other work.
Migrated to another repo 👍
Another related case to solve is this: https://github.com/wolfi-dev/advisories/actions/runs/7719825548/job/21043730046?pr=1036#step:5:26 ...where it's not the fixed version that was removed, but a version before it, which would (as a side effect) cause the...