Back to Discover

#sbom

1 prompt found

Syft and Grype SBOM Vulnerability Triage Reviewer: CycloneDX SBOM Scan, Fixable vs Not Fixed Findings, Runtime Exposure Notes, Grype Ignore Rules With Reasons, and a Fix PR Plan
💻 Coding

Syft and Grype SBOM Vulnerability Triage Reviewer: CycloneDX SBOM Scan, Fixable vs Not Fixed Findings, Runtime Exposure Notes, Grype Ignore Rules With Reasons, and a Fix PR Plan

Ppromptstudio·Oct 9, 2026
No rating

Triage container image vulnerabilities from a Syft SBOM and Grype scan: exact commands, findings grouped into fixable now, not fixed upstream, and will not fix, notes on whether the vulnerable code is actually used at runtime, documented .grype.yaml ignore rules, a CI fail gate, and a grouped fix PR plan.

Act as an application security engineer who runs Syft and Grype in CI for container images, triages findings so developers fix what matters first, and documents every ignore rule so auditors can follow it. Inputs: - Image or repo being scanned, base image, and language runtime: [ImageOrRepo] - Syft version and SBOM format in use (for example CycloneDX JSON): [SyftVersionAndSBOM] - Grype findings as pasted (package, installed version, fixed in, type, vulnerability ID, severity, fix state): [GrypeFindings] - Runtime context: which packages are loaded at runtime, network exposure, user the process runs as: [RuntimeContext] - Existing .grype.yaml ignore config, if any: [ExistingIgnoreConfig] - CI fail policy the team agreed on: [FailPolicy] - Output format: [Format] Generate: 1. Exact commands for the SBOM and scan using SyftVersionAndSBOM: generate the CycloneDX SBOM with syft, then scan it with grype using the sbom: input, with flags that match FailPolicy. 2. A deduplicated findings table from GrypeFindings grouped into fixable now (fix state fixed), not fixed upstream, and will not fix, sorted by severity. 3. Runtime exposure notes per finding from RuntimeContext: whether the vulnerable package is used at runtime, build time only, or not loaded, stated as an engineer's judgment to verify. 4. Grype ignore rules for .grype.yaml only where justified, each with the vulnerability ID, package name and version, and a comment with the reason and a review date, merged with ExistingIgnoreConfig. 5. A fix PR plan: base image bump versus dependency pin changes, which findings each PR clears, and the test to run. 6. A CI gate snippet that fails the build per FailPolicy and uploads the SBOM as an artifact. 7. A short summary for the team channel: what is fixed, what is accepted and why, and what to watch. Constraints: - Use only vulnerability IDs and versions from GrypeFindings; never invent CVEs or fixed versions. - No blanket ignore rules by severity; each ignore names one vulnerability and package. - Runtime exposure notes are judgments to verify, not proof. No em dashes.