Vulnerability insights through SBOM #1590
Unanswered
thomasvandeweijer
asked this question in
Q&A
Replies: 1 comment
-
Hello, SBOM is created based on the generic image content1 so it should not have the build tools listed inside (e.g: you can't find I don't have enough knowledge on this topic to know if SBOM is the right source for vulnerability detection but looking at the file content and its integration with tools like There are two alternatives ways to get included packages versions:
Footnotes |
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
Hi,
I'm currently trying to get better insights of active vulnerabilities on my systems. To do this for Flatcar I'm currently loading the
flatcar_production_image_sbom.json
file into Trivy, however I suspect this SBOM might have more packages than are actually in the image I'm loading (flatcar_production_pxe.vmlinuz
andflatcar_production_pxe_image.cpio.gz
).Based on these suspicions I have a few questions:
Any other suggestions/recommendations are also welcome, I'm still searching for the best approach.
Beta Was this translation helpful? Give feedback.
All reactions