Go binaries that currently get (devel)
as the version should instead stub UNKNOWN
based on the compliance policy
#3324
Labels
enhancement
New feature or request
What would you like to be added:
With the recent introduction of raising up unknowns in the SBOM along with a compliance policy for determining how the unknown components should be represented, I think it would be good to treat go binaries with a value of
(devel)
in the same way as unknown versions for all other ecosystems.Why is this needed:
To unify the treatment of unknown values across all ecosystems.
Additional context:
This would likely be coupled with related changes on the grype side most of which is discussed in https://anchorecommunity.discourse.group/t/grype-reporting-vulns-for-unknown-versions/174/7
The text was updated successfully, but these errors were encountered: