Skip to content

914694/vulnerability-match-labels

 
 

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

148 Commits
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

vulnerability-match-labels

This repo contains labeled vulnerability-package match pairs for select container images. These labels are used as a ground truth for evaluating the performance of vulnerability scanner tools (such as grype). The label data structure is governed by the artifact.LabelEntry from yardstick, the tool used to create these labels.

SBOMs for images with labels are stored as artifacts within the ghcr.io/anchore/vml-sbom/* container registry for convenience.

To see this data in action see test/quality in the grype repo.

About

Labeled vulnerability-package match pairs used as ground truth to evaluate vulnerability scanners

Resources

License

Stars

Watchers

Forks

Releases

No releases published

Packages

 
 
 

Contributors

Languages

  • Python 84.4%
  • Makefile 15.6%