boostsecurityio / lotp

boostsecurityio/lotp
Apache License 2.0
102 stars 6 forks source link

[LOTP] Add grype #21

Closed fproulx-boostsecurity closed 9 months ago

fproulx-boostsecurity commented 9 months ago

Description of the LOTP tool

Grype is an SCA tool that can be configured we a config file.

Configuration files

https://github.com/anchore/grype#configuration

looks like it might but be possible to achieve some RCE by overriding a Docker image it uses ? TBD?

This is still very speculative.

fproulx-boostsecurity commented 9 months ago

Hmmm probably ok