Skip to content

Triage agent for golang CVEs does not look into SBOMs #623

Description

@zdohnal

Description

Golang uses static linking of sources which are downloaded during build, so the final rpm has bundled affected code which can be found out only via inspecting SBOM of the package. Every package which uses statically linked languages are affected by this.

Benefit

More precise triage results of agent for golang CVEs triage process.

Importance

Many new projects use statically linked languages, so CVE triage of them by Ymir is rendered useless for such CVEs.

Workaround

  • There is an existing workaround that can be used until this feature is implemented.

Participation

  • I am willing to submit a pull request for this issue. (Packit team is happy to help!)

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions