openclarity / vmclarity

VMClarity is a tool for agentless detection and management of Virtual Machine Software Bill Of Materials (SBOM) and vulnerabilities
openclarity.io
Apache License 2.0
93 stars 22 forks source link

Plugin findings reconciliation improvements #1849

Open ramizpolic opened 1 week ago

ramizpolic commented 1 week ago

Overview

Currently, plugin findings are simply added/updated to the db layer from asset scan processor https://github.com/openclarity/vmclarity/blob/main/orchestrator/processor/assetscan/plugins.go. We should ensure that plugin findings are properly reconciled in order to