# July 3rd | Open Source Gardening | Live Stream

**URL:** <https://anchorecommunity.discourse.group/t/july-3rd-open-source-gardening-live-stream/486>\
**Category:** Announcements\
**Tags:** video, gardening\
**Created:** [June 30, 2025, 3:37pm UTC](https://anchorecommunity.discourse.group/t/july-3rd-open-source-gardening-live-stream/486 "2025-06-30T15:37:34Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![popey](https://yyz2.discourse-cdn.com/free1/user_avatar/anchorecommunity.discourse.group/popey/32/429_2.png) [@popey](https://anchorecommunity.discourse.group/u/popey)\
**Post date:** [June 30, 2025, 3:37pm UTC](https://anchorecommunity.discourse.group/t/july-3rd-open-source-gardening-live-stream/486/1 "2025-06-30T15:37:34Z")

</div>

# 👋 Hello everyone!

We’re back with the Anchore Open Source team running a [live stream](https://www.youtube.com/live/K4dohiNHdP0) to discuss issues, pull requests, and future [roadmap](https://github.com/orgs/anchore/projects/22/views/18) planning in our [SBOM](https://anchore.com/sbom) and [vulnerability](https://anchore.com/container-vulnerability-scanning/) tools.

⏰ Starts at 2025-07-03T19:00:00Z for about an hour.

Expect engineering and project management discussions, a bit of GitHub issue gardening on [Syft](https://github.com/anchore/syft), [Grype](https://github.com/anchore/grype), and the rest of the [family](https://github.com/anchore).

Join us today for a relaxed, educational, and productive live stream.

[![](https://global.discourse-cdn.com/free1/uploads/anchorecommunity/original/1X/2756cae5f9b0d29d80173281e3904712fb13a8a8.jpeg "Live SBOM & Security Fixes: Anchore Devs Improve Syft & Grype (July 3rd)") ](https://www.youtube.com/watch?v=K4dohiNHdP0)

## Topics

- [Issues](https://github.com/search?q=org%3Aanchore+label%3Aneeds-discussion&type=issues&s=updated&o=desc) - Open issues with “needs-discussion” label
- [Pull Requests](https://github.com/search?q=org%3Aanchore+label%3Aneeds-discussion&type=pullrequests&s=updated&o=desc) - Open PRs with “needs-discussion” label
- [Discourse topics](https://anchorecommunity.discourse.group/filter?q=posts-max:2%20category%3Asyft%2Cgrype%2Cgeneral%20status%3Aopen%20status%3Apublic%20order%3Alatest-post) - Open topics from #General #Syft and #Grype with few or no replies
- Questions from the audience

---

<div class="post-metadata">

**Author:** ![TimBrown1611](https://yyz2.discourse-cdn.com/free1/user_avatar/anchorecommunity.discourse.group/timbrown1611/32/223_2.png) [@TimBrown1611](https://anchorecommunity.discourse.group/u/TimBrown1611)\
**Post date:** [July 3, 2025, 5:39pm UTC](https://anchorecommunity.discourse.group/t/july-3rd-open-source-gardening-live-stream/486/2 "2025-07-03T17:39:29Z")

</div>

> <https://github.com/anchore/vunnel/pull/818>
>
> This PR adds EOL information to the DB.

---

<div class="post-metadata">

**Author:** ![popey](https://yyz2.discourse-cdn.com/free1/user_avatar/anchorecommunity.discourse.group/popey/32/429_2.png) [@popey](https://anchorecommunity.discourse.group/u/popey)\
**Post date:** [July 21, 2025, 11:32am UTC](https://anchorecommunity.discourse.group/t/july-3rd-open-source-gardening-live-stream/486/3 "2025-07-21T11:32:30Z")

</div>

Here are the notes from our latest “Open Source Gardening” session, where we triaged bugs, discussed pull requests, and worked on improving our open-source tools.

### [Syft Issue #3948: `syft attest` does not create a binary relationship for the subject](https://www.google.com/search?q=%5Bhttps://github.com/anchore/syft/issues/3948%5D(https://github.com/anchore/syft/issues/3948))

The team, including discussed a bug in Syft where the `syft attest` command fails to create a binary relationship for the subject, resulting in an incomplete attestation. This was identified as a good first issue for a new contributor to pick up. The problem lies in the relationship creation process, which needs to be corrected to ensure the generated attestations are accurate and complete.

### [Grype Issue #1454: Display licenses for matched packages](https://github.com/anchore/grype/issues/1454)

Next, the team looked at a feature request for Grype. The request is to display the license of each package that has a vulnerability. This would provide users with more context about the packages they are using and their associated licenses, which is particularly useful when a vulnerable package is found. The team agreed this would be a valuable addition to Grype’s output.

### [Vunnel PR #818: Add NVD data source](https://github.com/anchore/vunnel/pull/818)

Towards the end of the stream, the team reviewed a pull request for Vunnel. This PR adds a new data source for the National Vulnerability Database (NVD). The team was pleased to see this community contribution and, after a brief review, decided to merge it. This enhancement will allow Vunnel to pull in even more vulnerability data, making Grype’s scans more comprehensive.

We hope this summary is helpful. We encourage you to get involved in our projects on [GitHub](https://github.com/anchore). See you at the next live stream!
