Skip to content

Go binaries that currently get (devel) as the version should instead stub UNKNOWN based on the compliance policy #3324

@westonsteimel

Description

@westonsteimel

What would you like to be added:

With the recent introduction of raising up unknowns in the SBOM along with a compliance policy for determining how the unknown components should be represented, I think it would be good to treat go binaries with a value of (devel) in the same way as unknown versions for all other ecosystems.

Why is this needed:

To unify the treatment of unknown values across all ecosystems.

Additional context:
This would likely be coupled with related changes on the grype side most of which is discussed in https://anchorecommunity.discourse.group/t/grype-reporting-vulns-for-unknown-versions/174/7

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or request

    Type

    No type

    Projects

    Status

    Done

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions