fix: Prevent grouped vulnerability entries by including target and package path #2140
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Description
This PR addresses an issue in the
collectVulnerabilityIdReports
method where only one metric was being reported for multiple binaries with the same Vulnerability ID within the same image. The root cause was that the method only considered theVulnerabilityID
when determining uniqueness, causing subsequent findings with the same ID to be ignored.Changes Made:
collectVulnerabilityIdReports
method to include additional attributes (Target
andPkgPath
), ensuring each vulnerability is uniquely identified based on its ID, target, and package path.vulnList
map to use the concatenated string ofVulnerabilityID
,Target
, andPkgPath
as the key.This change improves the accuracy of the vulnerability metrics reported, especially for images containing multiple binaries and applications with numerous dependencies, such as Java applications, where a CVE could be present in multiple libraries.
Related issues
Checklist