You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
What would you like to be added:
Syft does not appear to identify bash.preinst, which is present on many of the official Docker images.
Why is this needed:
Syft should be able to identify common executables at least as expected/known rather than unknown.
Additional context:
In the official docker images, as of this writing, there are 33 instances of this at /var/lib/dpkg/info/bash.preinst, which do not appear to be associated to any of the package-manager installed packages. From some basic web search, it looks like this may be a one-time script to associate /bin/sh with /bin/bash in some manner, but more investigation is needed where it comes from and why it doesn't get removed for proper classification.
The text was updated successfully, but these errors were encountered:
What would you like to be added:
Syft does not appear to identify
bash.preinst
, which is present on many of the official Docker images.Why is this needed:
Syft should be able to identify common executables at least as expected/known rather than unknown.
Additional context:
In the official docker images, as of this writing, there are 33 instances of this at
/var/lib/dpkg/info/bash.preinst
, which do not appear to be associated to any of the package-manager installed packages. From some basic web search, it looks like this may be a one-time script to associate/bin/sh
with/bin/bash
in some manner, but more investigation is needed where it comes from and why it doesn't get removed for proper classification.The text was updated successfully, but these errors were encountered: