Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Support Fedora #121

Open
urbaniak opened this issue Aug 19, 2019 · 15 comments
Open

Support Fedora #121

urbaniak opened this issue Aug 19, 2019 · 15 comments
Labels
help wanted Denotes an issue that needs help from a contributor. Must meet "help wanted" guidelines. kind/feature Categorizes issue or PR as related to a new feature. priority/backlog Higher priority than priority/awaiting-more-evidence. scan/vulnerability Issues relating to vulnerability scanning

Comments

@urbaniak
Copy link

Any chances getting support for Fedora?

@urbaniak urbaniak added the kind/deprecation Categorizes issue or PR as related to a feature/enhancement marked for deprecation. label Aug 19, 2019
@knqyf263
Copy link
Collaborator

@urbaniak Thank you for your request. Although I want to support Fedora, I don't know whether Fedora has the security advisory. Trivy needs the security advisory by the distribution to detect vulnerabilities. Let me know if you know anything.

@ghost
Copy link

ghost commented Aug 24, 2019

Hello @knqyf263 ,
I think that you need to use this url to restrict to security : https://bodhi.fedoraproject.org/updates/?type=security
It also offers an RSS : https://bodhi.fedoraproject.org/rss/updates/?type=security
Fedora has others things about Updates and Security that you can find in the wiki : https://fedoraproject.org/wiki/Security_Bugs#Fedora_Security_Advisories
Regards

@knqyf263
Copy link
Collaborator

@Colundrum Great! This is valuable information. How many users are using fedora on container?

@ghost
Copy link

ghost commented Aug 25, 2019

@knqyf263 statistics for fedora official docker images are here : https://hub.docker.com/v2/repositories/library/fedora/
I read at this time : "pull_count": 49053602

@knqyf263
Copy link
Collaborator

@Colundrum Thank you for the information. It's large number. It might be better to support Fedora.
Welcome contributor!

@knqyf263 knqyf263 added kind/feature Categorizes issue or PR as related to a new feature. priority/backlog Higher priority than priority/awaiting-more-evidence. and removed kind/deprecation Categorizes issue or PR as related to a feature/enhancement marked for deprecation. labels Apr 30, 2020
@mfrancisc
Copy link

@knqyf263 I'm interested in having fedora support as well. I've started debugging trivy CLI in order to have an idea about the architecture.

Can you please provide some high level guidance on how to approach this contributions?
Should I start from trivy-db or fanal repository?

Thanks

@knqyf263
Copy link
Collaborator

First of all, we have to parse Fedora security advisories and they need to be committed to vuln-list.
https://bodhi.fedoraproject.org/updates/?type=security

The update script must be in vuln-list-update.

But I've not found structured advisories like JSON or YAML yet. Looks like RSS is missing some information such as OS versions. We have to look for it at first.

@knqyf263
Copy link
Collaborator

@mfrancisc Could you open a PR in vuln-list-update? We already have a PR we were working on, but you can open a new one.
aquasecurity/vuln-list-update#30

@knqyf263 knqyf263 added the help wanted Denotes an issue that needs help from a contributor. Must meet "help wanted" guidelines. label Apr 20, 2021
@mfrancisc
Copy link

@knqyf263 I can have a look and see if I can find a way to integrate the missing information (OS versions and others if needed).
Should I start from the code in that PR? why was that closed?

liamg pushed a commit that referenced this issue Jun 7, 2022
* fix: Due read after write consistency in S3 missingLayers called the actual object that created cache 403 response
This change creating index file for each object so missingLayers will not hit object that not exist.

* fix comments error description

Co-authored-by: oranmoshai <[email protected]>
liamg pushed a commit that referenced this issue Jun 7, 2022
* fix: Due read after write consistency in S3 missingLayers called the actual object that created cache 403 response
This change creating index file for each object so missingLayers will not hit object that not exist.

* fix comments error description

Co-authored-by: oranmoshai <[email protected]>
josedonizetti referenced this issue in josedonizetti/trivy Jun 24, 2022
feat: add unit tests for AWS EFS rules
@Loki-Afro
Copy link

Loki-Afro commented Sep 8, 2022

whats the status here? seems like fedora is not supported but there already was once a prepared pr for that?

since i'm new to this topic, is this about adding fedora to the "scanable base images" or to have installable rpms for fedora? :D

@danielefranceschi
Copy link

Seems like #1616 has been closed for inactivity. Any other news so far?

@shagun1802
Copy link

Any update so far? Has trivy started supporting fedora images?

1 similar comment
@lucasarrudatrustly
Copy link

Any update so far? Has trivy started supporting fedora images?

@itaysk itaysk added the scan/vulnerability Issues relating to vulnerability scanning label Feb 11, 2023
@logicito
Copy link

logicito commented Jun 8, 2023

I am very interested in using it with Fedora 38 as well

@lmilbaum
Copy link

I also interested in using it with all Fedora versions

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
help wanted Denotes an issue that needs help from a contributor. Must meet "help wanted" guidelines. kind/feature Categorizes issue or PR as related to a new feature. priority/backlog Higher priority than priority/awaiting-more-evidence. scan/vulnerability Issues relating to vulnerability scanning
Projects
Status: No status
Development

Successfully merging a pull request may close this issue.

10 participants