You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Both syft and grype are failing the Binary-Artifacts check due to files in the test-fixtures directories. Based on ossf/scorecard#1256 (comment) in ossf/scorecard#1256, these would automatically be discarded if they were in a directory called testdata, so may need some enhancements to scorecard itself to consider other names for test directories (or have some sort of project-level configuration that gets taken into account)
What would you like to be added:
We recently ran the
ossf/scorecard
1 over theSyft
project, found some vulnerabilities, here is the output of the scan:$ docker run -e GITHUB_AUTH_TOKEN=$GITHUB_TOKEN gcr.io/openssf/scorecard:stable --repo https://github.com/developer-guy/syft
Why is this needed:
To make
Syft
more secure.Additional context:
cc: @wagoodman @luhring @Dentrax
Footnotes
https://github.com/ossf/scorecard ↩
The text was updated successfully, but these errors were encountered: