Skip to content
Discussion options

You must be logged in to vote

Answers from Flavio from Slack

https://suse.slack.com/archives/C08GX5XJ996/p1759907629206429?thread_ts=1759900625.194909&cid=C08GX5XJ996

Could you please confirm if this approach is correct?

This is correct. It's however important for you to understand why this is happening, and how to handle that.
A report might include results about system packages and also binaries that have not been installed via the package manager.
Everything has to be put into the same table.

However it's important that the user knows that /bin/foo is affected by a CVE because it's using an outdated version of the go compiler. The entry in the table should be about /bin/foo, not the go compiler.
Of course that me…

Replies: 2 comments 2 replies

Comment options

You must be logged in to vote
0 replies
Answer selected by xingzhang-suse
Comment options

You must be logged in to vote
2 replies
@xingzhang-suse
Comment options

xingzhang-suse Oct 9, 2025
Maintainer Author

@fabriziosestito
Comment options

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
3 participants