Replies: 1 comment 2 replies
-
ALAS is an Amazon Linux specific vulnerability identifier. Dependency-Track does not natively support ALAS, but to my knowledge, ALAS identifier are not unique, meaning that they typically always reference one or more CVEs. |
Beta Was this translation helpful? Give feedback.
2 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
Hi Team,
Currently i make some comparison between the Grype and DT. To generate the Cyclonedx SBOM i use Syft. But somehow the Grype can detect the Vulnerability from ALAS but not with DT
Is it because the DT analyzers, which is no one is refer to the ALAS?
Thank You
Beta Was this translation helpful? Give feedback.
All reactions