dep-scan icon indicating copy to clipboard operation
dep-scan copied to clipboard

Accepting Trivy and Grype vulnerabilities for prioritization

Open prabhu opened this issue 2 years ago • 1 comments

Why can't dep-scan accept existing vulnerability data in vex and other formats and prioritize it by understanding the application context? The key differentiation aspects of dep-scan are the CVE insights and prioritization based on usage and exploitability.

dep-scan currently happens to generate both SBoM and the vulnerability list. If the --bom argument is provided, dep-scan skips generating the SBoM and moves on to the next step, generating the vulnerability list. A new argument, --vuln-list, could be added to accept a pre-generated list.

prabhu avatar Dec 02 '22 12:12 prabhu

Would really like to able to ingest pre-created SBOMs. Any chance of getting this supported?

Edit: nvm, that is supported!

audunmo avatar Jan 11 '24 12:01 audunmo