wolfictl icon indicating copy to clipboard operation
wolfictl copied to clipboard

A CLI used to work with the Wolfi OSS project

Results 98 wolfictl issues
Sort by recently updated
recently updated
newest added

Bumps [github.com/anchore/grype](https://github.com/anchore/grype) from 0.79.6 to 0.80.0. Release notes Sourced from github.com/anchore/grype's releases. v0.80.0 Added Features Add info subcommand in order to query grype db vulnerabilities [#1629 #2031 @​tomersein] Bug Fixes...

dependencies
go

I could not find any license information for the secdb data for wolfi and chainguard. Can you clarify what would be the license? These are the data published at: -...

bug
needs-triage

Bumps [github.com/tmc/dot](https://github.com/tmc/dot) from 0.0.0-20210901225022-f9bc17da75c0 to 0.2.0. Commits See full diff in compare view [![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=github.com/tmc/dot&package-manager=go_modules&previous-version=0.0.0-20210901225022-f9bc17da75c0&new-version=0.2.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) You can trigger a rebase of this PR by commenting `@dependabot rebase`. [//]: #...

dependencies
go

Move a package's advisories into a new package. This command will move most advisories for the given package into a new package. And rename the package to the new package...

``` go run . scan my-custom-package --remote --repository https://my/custom/respository ``` ``` --repository string URL of the Wolfi package repository (default "https://packages.wolfi.dev/os") ```

This PR adds a new linter to check if version-stream correctly set for the given package: * With a ReGeX, it checks whether package name contains version stream suffix *...

The `guide` command was designed to solve for the issue of `wolfictl adv (create|update)` having very specific expectations for a user to have already cloned the relevant advisories repo and...

enhancement
needs-triage

Today the command manages the clone and modification of advisory data in a temporary directory, in hopes of opening a PR with these changes on behalf of the user. But...

enhancement
needs-triage

It seems that the "submit PR" function requires a GITHUB_TOKEN (correct?) so this PR allows the user to simply print the changed YAMLs to the console to submit to advisory...