# February 6th | Open Source Gardening | Live Stream

**URL:** <https://anchorecommunity.discourse.group/t/february-6th-open-source-gardening-live-stream/328>\
**Category:** Announcements\
**Tags:** video, gardening\
**Created:** [February 3, 2025, 2:15pm UTC](https://anchorecommunity.discourse.group/t/february-6th-open-source-gardening-live-stream/328 "2025-02-03T14:15:46Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![popey](https://yyz2.discourse-cdn.com/free1/user_avatar/anchorecommunity.discourse.group/popey/32/429_2.png) [@popey](https://anchorecommunity.discourse.group/u/popey)\
**Post date:** [February 3, 2025, 2:15pm UTC](https://anchorecommunity.discourse.group/t/february-6th-open-source-gardening-live-stream/328/1 "2025-02-03T14:15:46Z")

</div>

# 👋 Hello everyone!

We’re back with Anchore Open Source team running a [live stream](https://www.youtube.com/watch?v=Qq_U6SHwfQw) to discuss issues, pull requests and future [roadmap](https://github.com/orgs/anchore/projects/22/views/18) planning in our [SBOM](https://anchore.com/sbom) and [vulnerability](https://anchore.com/container-vulnerability-scanning/) tools.

⏰ Starts at 2025-02-06T20:00:00Z for about an hour.

Expect engineering and project management discussions, a bit of GitHub issue gardening on [Syft](https://github.com/anchore/syft), [Grype](https://github.com/anchore/grype), and the rest of the [family](https://github.com/anchore).

Join us today for a relaxed, educational and productive live stream.

[![](https://global.discourse-cdn.com/free1/uploads/anchorecommunity/original/1X/2756cae5f9b0d29d80173281e3904712fb13a8a8.jpeg "6th February | Open Source Gardening | Live with Anchore Devs") ](https://www.youtube.com/watch?v=Qq_U6SHwfQw)

## Topics

- [Issues](https://github.com/search?q=org%3Aanchore+label%3Aneeds-discussion&type=issues&s=updated&o=desc) - Open issues with “needs-discussion” label
- [Pull Requests](https://github.com/search?q=org%3Aanchore+label%3Aneeds-discussion&type=pullrequests&s=updated&o=desc) - Open PRs with “needs-discussion” label
- [Discourse topics](https://anchorecommunity.discourse.group/filter?q=posts-max:2%20category%3Asyft%2Cgrype%2Cgeneral%20status%3Aopen%20status%3Apublic%20order%3Alatest-post) - Open topics from #General #Syft and #Grype with few or no replies
- Questions from the audience

---

<div class="post-metadata">

**Author:** ![TimBrown1611](https://yyz2.discourse-cdn.com/free1/user_avatar/anchorecommunity.discourse.group/timbrown1611/32/223_2.png) [@TimBrown1611](https://anchorecommunity.discourse.group/u/TimBrown1611)\
**Post date:** [February 3, 2025, 5:05pm UTC](https://anchorecommunity.discourse.group/t/february-6th-open-source-gardening-live-stream/328/2 "2025-02-03T17:05:52Z")

</div>

Hi @popey , hope you are doing well 🙂  
it has been a while since someone continued reviewing my PRs, I would appreciate for some comments 🙂

> <https://github.com/anchore/syft/pull/3138>
>
> This PR tries to solve the squash-with-all-layer resolver issue, aligned to the …newest version of syft.
> Please let me know how to proceed further, I guess the solution here is not perfect, but it does knows how to handle deleted packages.
> 
> part of - https://github.com/anchore/syft/issues/15

> <https://github.com/anchore/grype/pull/2271>
>
> closes - https://github.com/anchore/grype/issues/2264
> 
> this PR aims to add a n…ew field to match details which specifies the suggested fixed version

---

<div class="post-metadata">

**Author:** ![popey](https://yyz2.discourse-cdn.com/free1/user_avatar/anchorecommunity.discourse.group/popey/32/429_2.png) [@popey](https://anchorecommunity.discourse.group/u/popey)\
**Post date:** [February 5, 2025, 9:33am UTC](https://anchorecommunity.discourse.group/t/february-6th-open-source-gardening-live-stream/328/3 "2025-02-05T09:33:33Z")

</div>

Yeah, sorry about that. There’s been some illness on the team, and some features that needed to land, that we had to focus on. Once everyone is fighting fit, and we get past these chunky features, we should be able to circle back to these. Really sorry about that 🙏

---

<div class="post-metadata">

**Author:** ![TimBrown1611](https://yyz2.discourse-cdn.com/free1/user_avatar/anchorecommunity.discourse.group/timbrown1611/32/223_2.png) [@TimBrown1611](https://anchorecommunity.discourse.group/u/TimBrown1611)\
**Post date:** [February 5, 2025, 1:07pm UTC](https://anchorecommunity.discourse.group/t/february-6th-open-source-gardening-live-stream/328/4 "2025-02-05T13:07:01Z")

</div>

hi -

> <https://github.com/anchore/syft/commit/684b6e3f9809a95ba08cb83c8d0661ab22eed8cc>
>
> \* add file catalogers to selection configuration
> 
> Signed-off-by: Alex Goodman \<w…agoodman@users.noreply.github.com\>
> 
> \* fix typos
> 
> Signed-off-by: Alex Goodman \<wagoodman@users.noreply.github.com\>
> 
> \* warn when there is conflicting file cataloging configuration
> 
> Signed-off-by: Alex Goodman \<wagoodman@users.noreply.github.com\>
> 
> \* allow for explicit removal of all package and file tasks
> 
> Signed-off-by: Alex Goodman \<wagoodman@users.noreply.github.com\>
> 
> \* address PR feedback
> 
> Signed-off-by: Alex Goodman \<wagoodman@users.noreply.github.com\>
> 
> \---------
> 
> Signed-off-by: Alex Goodman \<wagoodman@users.noreply.github.com\>

i see this changed was merged. would appreciate to explain about it 🙂

---

<div class="post-metadata">

**Author:** ![popey](https://yyz2.discourse-cdn.com/free1/user_avatar/anchorecommunity.discourse.group/popey/32/429_2.png) [@popey](https://anchorecommunity.discourse.group/u/popey)\
**Post date:** [February 6, 2025, 9:00pm UTC](https://anchorecommunity.discourse.group/t/february-6th-open-source-gardening-live-stream/328/5 "2025-02-06T21:00:15Z")

</div>

Things we discussed this week:

- [Our Community Newsletter](https://get.anchore.com/anchore-community/) - Sign up!
- [SBOM 101 eBook](https://github.com/anchore/sbom-ebook) - Read and/or contribute!
  - [Announcement Blog Post](https://anchore.com/blog/sboms-101-a-free-open-source-ebook-for-the-devsecops-community/)

- [feat: 3626 add option enable license content; disable by default by spiffcs · Pull Request #3631 · anchore/syft · GitHub](https://github.com/anchore/syft/pull/3631)
- [Sbommage](https://github.com/popey/sbommage) - Shameless plug!

Issues needing discussion

- [Should only check maven central if pom info is missing · Issue #2216 · anchore/grype · GitHub](https://github.com/anchore/grype/issues/2216)
- [Report errors directly to the user and document · Issue #2393 · anchore/grype · GitHub](https://github.com/anchore/grype/issues/2393)
- [Support SBOM creation for container image indexes · Issue #1683 · anchore/syft · GitHub](https://github.com/anchore/syft/issues/1683)
  - [GitHub - kubernetes-sigs/bom: A utility to generate SPDX-compliant Bill of Materials manifests](https://github.com/kubernetes-sigs/bom)
  - [Support for image indexes with multiple manifests · Issue #175 · anchore/stereoscope · GitHub](https://github.com/anchore/stereoscope/issues/175)
  - [spdx-examples/semantics/oci-multiarch-index.md at master · spdx/spdx-examples · GitHub](https://github.com/spdx/spdx-examples/blob/master/semantics/oci-multiarch-index.md)

- [Include the OS Information available in the SBOM model in the SPDX reports by josegomezr · Pull Request #3462 · anchore/syft · GitHub](https://github.com/anchore/syft/pull/3462) / [OS information missing in SPDX format SBOM for a container image · Issue #3012 · anchore/syft · GitHub](https://github.com/anchore/syft/issues/3012)

Requested discussion by @TimBrown1611

- [Add file catalogers to selection configuration (#3505) · anchore/syft@684b6e3 · GitHub](https://github.com/anchore/syft/commit/684b6e3f9809a95ba08cb83c8d0661ab22eed8cc)
