Skip to content

Commit

Permalink
fix: suppress some known incorrect vendor candidates for npm CPEs (#1659
Browse files Browse the repository at this point in the history
)

Signed-off-by: Weston Steimel <weston.steimel@anchore.com>
  • Loading branch information
westonsteimel authored Mar 7, 2023
1 parent 7cfdffa commit 096d2b7
Showing 1 changed file with 21 additions and 0 deletions.
21 changes: 21 additions & 0 deletions syft/pkg/cataloger/common/cpe/candidate_by_package_type.go
Original file line number Diff line number Diff line change
Expand Up @@ -350,6 +350,27 @@ var defaultCandidateRemovals = buildCandidateRemovalLookup(
candidateKey{PkgName: "redis"},
candidateRemovals{VendorsToRemove: []string{"redis"}},
},
// NPM packages
{
pkg.NpmPkg,
candidateKey{PkgName: "redis"},
candidateRemovals{VendorsToRemove: []string{"redis"}},
},
{
pkg.NpmPkg,
candidateKey{PkgName: "php"},
candidateRemovals{VendorsToRemove: []string{"php"}},
},
{
pkg.NpmPkg,
candidateKey{PkgName: "delegate"},
candidateRemovals{VendorsToRemove: []string{"delegate"}},
},
{
pkg.NpmPkg,
candidateKey{PkgName: "docker"},
candidateRemovals{VendorsToRemove: []string{"docker"}},
},
})

// buildCandidateLookup is a convenience function for creating the defaultCandidateAdditions set
Expand Down

0 comments on commit 096d2b7

Please sign in to comment.