project-copacetic / copacetic

🧵 CLI tool for directly patching container images!
https://project-copacetic.github.io/copacetic/
Apache License 2.0
933 stars 62 forks source link

[DOC] Clarify vex output cannot be generated with update all #744

Open ashnamehrotra opened 1 month ago

ashnamehrotra commented 1 month ago

What kind of documentation improvement is needed?

None

What is the change that is needed?

Clarify Copa will not be able to provide any vex output with upgrade all approach since it doesn't have any info on CVEs associated with the package upgrades in https://project-copacetic.github.io/copacetic/website/output

Are you willing to submit PRs to contribute to documentation?

Nishant-k-sagar commented 1 month ago

Hey @ashnamehrotra, I have gone through the codebase structure in this repo, and can improve documentation, can you assign me this documentation update/change issue, and tell or guide me what specific output will you like to add in output.md

ashnamehrotra commented 1 month ago

@Nishant-k-sagar assigned, thanks! we just want to clarify that the vex output is only possible if using the patching approach with scan report