# Revisiting ownership-by-file-overlap relationships

**URL:** <https://anchorecommunity.discourse.group/t/revisiting-ownership-by-file-overlap-relationships/137>\
**Category:** General\
**Created:** [September 16, 2024, 7:05pm UTC](https://anchorecommunity.discourse.group/t/revisiting-ownership-by-file-overlap-relationships/137 "2024-09-16T19:05:37Z")\
**Posts on this page:** 1\
**Showing post:** 2

<div class="post-metadata">

**Author:** ![willmurphy](https://yyz2.discourse-cdn.com/free1/user_avatar/anchorecommunity.discourse.group/willmurphy/32/12_2.png) [@willmurphy](https://anchorecommunity.discourse.group/u/willmurphy)\
**Post date:** [November 26, 2024, 10:05pm UTC](https://anchorecommunity.discourse.group/t/revisiting-ownership-by-file-overlap-relationships/137/2 "2024-11-26T22:05:40Z")

</div>

As an aside, it looks like from [Exclude-binary-overlap-by-ownership flag is not working](https://anchorecommunity.discourse.group/t/exclude-binary-overlap-by-ownership-flag-is-not-working/248) some users expect that the exclude binary files by ownership overlap will _already_ remove other packages.

> [@kzantow](#):
>
> Beyond these purposes, I’m having a hard time finding the value of the relationships. Maybe Syft has an option to disable the deduplication if a user _really_ wants that, but why not just have a specific function to do so without adding relationships only to later remove them?

I think the concern here is that if I’m on a distro that only reports vulns after they’re patched, and I install an OS package that brings with it a Python package, then GHSA on the Python package is the best source of vulnerability data I have until the distro releases a patch or changes their reporting policy.

---

_[View the full topic](https://anchorecommunity.discourse.group/t/revisiting-ownership-by-file-overlap-relationships/137)._
