fix: add Grype version and vulnerability DB info to HTML template#3346
Open
hellozzm wants to merge 1 commit intoanchore:mainfrom
Open
fix: add Grype version and vulnerability DB info to HTML template#3346hellozzm wants to merge 1 commit intoanchore:mainfrom
hellozzm wants to merge 1 commit intoanchore:mainfrom
Conversation
Add Grype version (name + version) and vulnerability database metadata to the header section of the HTML vulnerability report template, so users can verify the tool and DB versions used to generate the report.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
The HTML vulnerability report template (
templates/html.tmpl) currently does not display the Grype version or vulnerability database version/date in the report header. This makes it impossible to determine from the report output whether it was generated with a recent version of Grype and an up-to-date vulnerability database.Fixes #2877
Changes
{{.Descriptor.Name}} {{.Descriptor.Version}}Testing
.Descriptorstruct (name,version,dbfields)