Skip to content

Known affected acceptance#1895

Open
crozzy wants to merge 2 commits into
quay:mainfrom
crozzy:known_affected_acceptance
Open

Known affected acceptance#1895
crozzy wants to merge 2 commits into
quay:mainfrom
crozzy:known_affected_acceptance

Conversation

@crozzy

@crozzy crozzy commented May 27, 2026

Copy link
Copy Markdown
Contributor

This PR adds

  1. A modification to the claircore auditor to process PackageNotVulnerable map.
  2. And example acceptance test showing how to asset not_affected status.

@crozzy crozzy force-pushed the known_affected_acceptance branch 3 times, most recently from ac9872a to 92a3657 Compare June 12, 2026 22:14
crozzy added 2 commits June 12, 2026 15:28
This extends the acceptance testing framework for the claircore auditor
by reading the PackageNotVulnerable section of the claircore
VulnerabilityReport.

Signed-off-by: crozzy <joseph.crosland@gmail.com>
This patch adds an acceptance test to check claircore is correctly
identifying PackageNotVulnerable data.

Signed-off-by: crozzy <joseph.crosland@gmail.com>
@crozzy crozzy force-pushed the known_affected_acceptance branch from 92a3657 to 47ecbf5 Compare June 12, 2026 22:28
@crozzy crozzy marked this pull request as ready for review June 12, 2026 22:31
@crozzy crozzy requested a review from a team as a code owner June 12, 2026 22:31
@crozzy crozzy requested review from hdonnay and removed request for a team June 12, 2026 22:31
// PackageNotVulnerable through AncestryPackage matching (Invert=true).
Name: "mta-rhel8-operator-protobuf",
Image: "quay.io/projectquay/clair-fixtures@sha256:1719cafe5b15c44bb1bb207bce1cc2a6ee7c1b097901d8fab61912ce298f40dd",
VEXURL: "https://security.access.redhat.com/data/csaf/v2/vex/2024/cve-2024-24786.json",

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We should make check this in to avoid flakes?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

1 participant