anchore / grype

A vulnerability scanner for container images and filesystems
Apache License 2.0
8.87k stars 575 forks source link

Add purls in sarif report #2254

Open GeorgeLS opened 1 week ago

GeorgeLS commented 1 week ago

Hello there! Seems like that purls are missing from Sarif reports of grype. I attempted adding those in the Sarif report. In order to do that I had to copy the deriveBomRef function that is being used in CycloneDx as well. I tried making deriveBomRef a member function of Package type in order to avoid duplication but I couldn't build the project locally.

Thanks, George