Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

DB diff vulnerability metadata #2443

Open
driessamyn opened this issue Feb 12, 2025 · 2 comments
Open

DB diff vulnerability metadata #2443

driessamyn opened this issue Feb 12, 2025 · 2 comments
Labels
enhancement New feature or request

Comments

@driessamyn
Copy link

What would you like to be added:

Would it be possible to include vulnerability metadata in the output of grype db diff?

And/or a (quick) way to look the metadata for a given vulnerabiliity.

Why is this needed:

The DB diff is useful to assess changes in the vulnerability profile without the need to rescan the sbom, but detail such as the severity would be useful.

Additional context:

If this isn't readily available now, would the team consider a contribution to add this?

@driessamyn driessamyn added the enhancement New feature or request label Feb 12, 2025
@kzantow
Copy link
Contributor

kzantow commented Feb 12, 2025

I should note: we are almost certainly removing the db diff command from Grype in the very near future, when moving to DB v6, since the DB structure has changed significantly and is much more difficult to "diff" in a meaningful way. However, there is new functionality to search the db in useful ways (via grype db search) which we believe will both provide a better experience to understand what's changed and be significantly more performant. Perhaps if you could outline the use case(s) you have, we could understand if it's already be supported or what we could do via db search to support it?

@driessamyn
Copy link
Author

Thanks. I saw another issue making a reference to it.
My usecase is to understand vulnerability changes without needing to rescan sboms.
A search that returns new, changed, removed vulnerabilities (from the db) since a given date would be fine, in fact probably a nicer interface.
But it feels a bit of a shame the diff provides 80% of the info, but not the vulnerability metadata.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New feature or request
Projects
Status: No status
Development

No branches or pull requests

2 participants