cbdq-io/docker-grype

Allow Generation of Missing Common Platform Enumerations

Closed this issue · 0 comments

Describe the solution you'd like
Grype can optionally generate CPEs for packages that are missing them.

Describe alternatives you've considered
Having the option set as on by default, but this should probably be left to the user (as it is in the underlying Grype command).

Additional context
See https://cpe.mitre.org/about/ for notes about CPEs.

An example of an occurrence can be seen in https://github.com/cbdq-io/docker-grype/runs/7037310023?check_suite_focus=true#step:9:872