Some question about VEX for library #7784
-
I understand that VEX is good for Image or Container or Software but does it also work for library ? Imagine that :
If someone else have a C project which depends on A (and so indirectly on B) This sounds a good idea. In this other hand that means that user should take lot of care about if its dependencies is direct or not ? Please let me know if I misunderstood something 🙏 |
Beta Was this translation helpful? Give feedback.
Replies: 1 comment 3 replies
-
Yes, Trivy supports that. I think this is what you're looking for. |
Beta Was this translation helpful? Give feedback.
Yes, Trivy supports that. I think this is what you're looking for.
https://aquasecurity.github.io/trivy/v0.56/docs/supply-chain/vex/file/#applying-vex-to-dependency-trees