chainguard-dev / bincapz

detect malicious program behaviors
Apache License 2.0
387 stars 24 forks source link

Tune packer rules to avoid false-positives #150

Closed tstromberg closed 3 months ago

tstromberg commented 3 months ago

I was seeing false-positives with these new rules in Wolfi, particularly with bazel. They are a bit more cautious now.

This now makes use of rule inheritance.