Closed luhring closed 1 year ago
Thank you, @luhring! Any thoughts from any of the proposed reviewers?
I say merge if @joshrwolf says merge. Any objections? Let's merge by 5 PM ET today unless someone speaks up.
for everyones peace of mind, here is where the image data is being pulled from. ignoring this image means we avoid double scanning (if grype can even effectively scan this format?)
(if grype can even effectively scan this format?)
Grype can scan crane pull
ed local images (using --format
s of either tarball
or oci
), but it doesn't expect to find images within other images IIRC
It's been failing consistently with:
(Latest job run: https://github.com/chainguard-dev/rumble/actions/runs/5506740051/jobs/10035870769)
Reproducible with:
📣 Feel free to just close this PR if there's a better immediate solution! 😃