💻 Coding

Syft and Grype SBOM Vulnerability Triage Reviewer: CycloneDX SBOM Scan, Fixable vs Not Fixed Findings, Runtime Exposure Notes, Grype Ignore Rules With Reasons, and a Fix PR Plan

Triage container image vulnerabilities from a Syft SBOM and Grype scan: exact commands, findings grouped into fixable now, not fixed upstream, and will not fix, notes on whether the vulnerable code is actually used at runtime, documented .grype.yaml ignore rules, a CI fail gate, and a grouped fix PR plan.

0.0
0Reviews
P
October 9, 2026

Prompt

Act as an application security engineer who runs Syft and Grype in CI for container images, triages findings so developers fix what matters first, and documents every ignore rule so auditors can follow it.

Inputs:
- Image or repo being scanned, base image, and language runtime: [ImageOrRepo]
- Syft version and SBOM format in use (for example CycloneDX JSON): [SyftVersionAndSBOM]
- Grype findings as pasted (package, installed version, fixed in, type, vulnerability ID, severity, fix state): [GrypeFindings]
- Runtime context: which packages are loaded at runtime, network exposure, user the process runs as: [RuntimeContext]
- Existing .grype.yaml ignore config, if any: [ExistingIgnoreConfig]
- CI fail policy the team agreed on: [FailPolicy]
- Output format: [Format]

Generate:
1. Exact commands for the SBOM and scan using SyftVersionAndSBOM: generate the CycloneDX SBOM with syft, then scan it with grype using the sbom: input, with flags that match FailPolicy.
2. A deduplicated findings table from GrypeFindings grouped into fixable now (fix state fixed), not fixed upstream, and will not fix, sorted by severity.
3. Runtime exposure notes per finding from RuntimeContext: whether the vulnerable package is used at runtime, build time only, or not loaded, stated as an engineer's judgment to verify.
4. Grype ignore rules for .grype.yaml only where justified, each with the vulnerability ID, package name and version, and a comment with the reason and a review date, merged with ExistingIgnoreConfig.
5. A fix PR plan: base image bump versus dependency pin changes, which findings each PR clears, and the test to run.
6. A CI gate snippet that fails the build per FailPolicy and uploads the SBOM as an artifact.
7. A short summary for the team channel: what is fixed, what is accepted and why, and what to watch.

Constraints:
- Use only vulnerability IDs and versions from GrypeFindings; never invent CVEs or fixed versions.
- No blanket ignore rules by severity; each ignore names one vulnerability and package.
- Runtime exposure notes are judgments to verify, not proof. No em dashes.

Instructions

Replace every [bracket] with your details before running. Works on ChatGPT, Claude, and Gemini.

Generated Output

This image was generated using the prompt above.

Syft and Grype SBOM Vulnerability Triage Reviewer: CycloneDX SBOM Scan, Fixable vs Not Fixed Findings, Runtime Exposure Notes, Grype Ignore Rules With Reasons, and a Fix PR Plan - Result

Examples

Example Input

ImageOrRepo: ghcr.io/acme/billing-api:2.8.1, base python:3.12-slim (Debian bookworm), FastAPI service
SyftVersionAndSBOM: Syft 1.x, CycloneDX JSON
GrypeFindings:
- zlib1g 1:1.2.13.dfsg-1, deb, CVE-2023-45853, Critical, fix state wont-fix
- setuptools 69.5.1, python, CVE-2024-6345, High, fixed in 70.0.0
- requests 2.31.0, python, CVE-2024-35195, Medium, fixed in 2.32.0
- idna 3.6, python, CVE-2024-3651, Medium, fixed in 3.7
- setuptools 69.5.1 listed twice (site-packages and pip vendor path)
RuntimeContext: app calls a partner API with requests; setuptools only used at image build; zlib used by Python itself, the vulnerable code is in the minizip part which the app does not call; runs as non root user 10001 behind an internal load balancer
ExistingIgnoreConfig: none
FailPolicy: fail on High or Critical that has a fix available; Medium tracked in tickets
Format: commands, table, exposure, .grype.yaml, PR plan, CI snippet, summary

Example Output

COMMANDS
syft ghcr.io/acme/billing-api:2.8.1 -o cyclonedx-json=sbom.cdx.json
grype sbom:sbom.cdx.json --only-fixed --fail-on high -o table
(Full report for tickets: grype sbom:sbom.cdx.json -o json > grype.json)

FINDINGS (deduplicated)
Fixable now
| Package | Installed | Fixed in | ID | Severity |
| setuptools | 69.5.1 | 70.0.0 | CVE-2024-6345 | High |
| requests | 2.31.0 | 2.32.0 | CVE-2024-35195 | Medium |
| idna | 3.6 | 3.7 | CVE-2024-3651 | Medium |
Will not fix (distro)
| zlib1g | 1:1.2.13.dfsg-1 | none | CVE-2023-45853 | Critical |
setuptools appeared twice (site-packages and pip vendor path); counted once, both paths cleared by the same upgrade.

RUNTIME EXPOSURE (to verify)
- setuptools CVE-2024-6345: build time only per RuntimeContext. Still fix: it is High with a fix, so FailPolicy blocks the build.
- requests CVE-2024-35195: used at runtime for partner API calls. Fix in this sprint.
- idna CVE-2024-3651: pulled in by requests, used at runtime when parsing hostnames. Fix with the requests bump.
- zlib1g CVE-2023-45853: Debian marks it will not fix; the vulnerable minizip code is not called by the app. Accept with a documented ignore and review date.

.grype.yaml
ignore:
  # zlib minizip issue; distro wont-fix; app does not use minizip. Owner: appsec. Review by 2027-01-15.
  - vulnerability: CVE-2023-45853
    package:
      name: zlib1g
      version: 1:1.2.13.dfsg-1
      type: deb

FIX PR PLAN
PR 1: dependency pins
- requirements.txt: requests>=2.32.0, idna>=3.7
- Dockerfile: pip install --upgrade "setuptools>=70.0.0" in the build stage, or remove setuptools from the final stage
- Clears CVE-2024-6345, CVE-2024-35195, CVE-2024-3651
- Test: unit tests plus the partner API contract test against staging
PR 2: base image refresh
- Rebuild on the latest python:3.12-slim digest and rescan; zlib1g stays ignored unless a fix lands.

CI GATE (GitHub Actions step)
- name: SBOM and scan
  run: |
    syft "$IMAGE" -o cyclonedx-json=sbom.cdx.json
    grype sbom:sbom.cdx.json --only-fixed --fail-on high
- uses: actions/upload-artifact@v4
  with:
    name: sbom
    path: sbom.cdx.json

TEAM SUMMARY
billing-api 2.8.1: three fixable findings (one High, two Medium) cleared by PR 1. One Critical in zlib1g is a distro will not fix in code we do not call; ignored with a reason and a January review. The build now fails on any fixable High or Critical.

Reviews (0)

Please login to leave a review.
Loading reviews...