anchore / anchore-engine

A service that analyzes docker images and scans for vulnerabilities
Apache License 2.0
1.58k stars 273 forks source link

deepin os #258

Open likhita-8091 opened 4 years ago

likhita-8091 commented 4 years ago

I would like to ask if it is possible to add a related image based on deepin os. I tried it and scanned the vulnerability without any results.

zhill commented 4 years ago

Thanks for the request. I've not looked into the cve sources for Deepin. At a quick glance, it does not look like the project maintains its own security feed for fix versions on its builds. Is there a vulnerability feed specifically for this distro?

likhita-8091 commented 4 years ago

There should be, but I don't know how to integrate into your project.

⁣获取 BlueMail for Android ​

2019年9月4日 上午6:04, 上午6:04,在 Zach Hill notifications@github.com 已写:

Thanks for the request. I've not looked into the cve sources for Deepin. At a quick glance, it does not look like the project maintains its own security feed for fix versions on its builds. Is there a vulnerability feed specifically for this distro?

-- You are receiving this because you authored the thread. Reply to this email directly or view it on GitHub: https://github.com/anchore/anchore-engine/issues/258#issuecomment-527658762

likhita-8091 commented 4 years ago

hi

zhill commented 4 years ago

I haven't yet found a vulnerability data source for this distro. Is there a link you can share?

likhita-8091 commented 4 years ago

I am not too sure, deepin os is based on the debian series. Deep Technology is a company in Wuhan, China. The official website of the company is: https://www.deepin.org/ The reason I raised this question is because of deepin The image built by the os platform can't be scanned, and the image built on the x86 platform is OK, but our requirement is not to build the image through the x86 platform.