Skip to content

Add missing package information for Sarif report #2267

Closed
@GeorgeLS

Description

@GeorgeLS

What would you like to be added:
I would like to have package information in the Sarif report.

Why is this needed:
If this information is present, then someone can correlate known vulnerabilities with packages they are using.

Additional context:
I've already opened a PR (#2254) to try and implement that feature.

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or request

    Type

    No type

    Projects

    Status

    Done

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions