Closed fproulx-boostsecurity closed 9 months ago
Grype is an SCA tool that can be configured we a config file.
https://github.com/anchore/grype#configuration
looks like it might but be possible to achieve some RCE by overriding a Docker image it uses ? TBD?
This is still very speculative.
Hmmm probably ok
Description of the LOTP tool
Grype is an SCA tool that can be configured we a config file.
Configuration files
https://github.com/anchore/grype#configuration
looks like it might but be possible to achieve some RCE by overriding a Docker image it uses ? TBD?
This is still very speculative.