project-copacetic / copacetic

🧵 CLI tool for directly patching container images!
https://project-copacetic.github.io/copacetic/
Apache License 2.0
1.06k stars 70 forks source link

[DOC] Clarify vex output cannot be generated with update all #744

Open ashnamehrotra opened 3 months ago

ashnamehrotra commented 3 months ago

What kind of documentation improvement is needed?

None

What is the change that is needed?

Clarify Copa will not be able to provide any vex output with upgrade all approach since it doesn't have any info on CVEs associated with the package upgrades in https://project-copacetic.github.io/copacetic/website/output

Are you willing to submit PRs to contribute to documentation?

Nishant-k-sagar commented 3 months ago

Hey @ashnamehrotra, I have gone through the codebase structure in this repo, and can improve documentation, can you assign me this documentation update/change issue, and tell or guide me what specific output will you like to add in output.md

ashnamehrotra commented 3 months ago

@Nishant-k-sagar assigned, thanks! we just want to clarify that the vex output is only possible if using the patching approach with scan report