Tim Gerla
Tim Gerla
Hi @mkesper, sorry for the very long delay replying here. We have recently added some binary detection capabilities to Syft. Do you want to give this a try with the...
We'll go ahead and close this issue but please feel free to reopen it if you have more questions.
Hey all, after some discussion we decided to try improving the `--output` help text and docs, and deprecate `--file`. You can of course still use shell redirection, too. Please see...
Hey @developer-guy, we are going through some old tickets and I wondered if this is still an issue for you, or if we can close it out? Thanks!
If anyone's interested in tackling this issue, you can start by looking at the structure here: https://github.com/anchore/syft/blob/main/syft/pkg/alpm_metadata.go#L17-L29 Notice that right now there is only one item with a CycloneDX tag...
Hi @DanHam, sorry for the very long delay replying to this ticket. Did you happen to see @julien-carsique-sonarsource's comment above with a patch for the completion script? It sounds like...
Hi @DanHam, thank you for confirming. I think the best thing we can do in the short term is update the documentation with this workaround. We'll go ahead and put...
Hey @devinrsmith, have you had a chance to try to reproduce this in your container yet? We have so far been unable to reproduce the problem here but we would...
Thanks @devinrsmith, this is helpful. On a hunch, can you try moving the tar file to /tmp and scanning it from there, and/or creating a new system user (without "dev"...
Hi @mmarseu, thanks for the suggestion. We think it makes sense to include full license text or license snippets where available, as an opt-in configuration. We've got some more design...