# Show each CVE only once i final results

**URL:** <https://anchorecommunity.discourse.group/t/show-each-cve-only-once-i-final-results/316>\
**Category:** Grype\
**Created:** [January 23, 2025, 10:38am UTC](https://anchorecommunity.discourse.group/t/show-each-cve-only-once-i-final-results/316 "2025-01-23T10:38:04Z")\
**Posts on this page:** 1\
**Showing post:** 2

<div class="post-metadata">

**Author:** ![willmurphy](https://yyz2.discourse-cdn.com/free1/user_avatar/anchorecommunity.discourse.group/willmurphy/32/12_2.png) [@willmurphy](https://anchorecommunity.discourse.group/u/willmurphy)\
**Post date:** [January 23, 2025, 3:05pm UTC](https://anchorecommunity.discourse.group/t/show-each-cve-only-once-i-final-results/316/2 "2025-01-23T15:05:18Z")

</div>

Hi @TimBrown1611 thanks for the suggestion!

My concern with this feature is that it would frustrate users, because they might see a CVE, and then upgrade the affected package, and then see it again.

I think a better workaround in the meantime is probably to run Grype and Syft on a subset of the system at a time. For example, you could run Syft with only the RPM cataloger enabled and pass the result to Grype, and then run Syft again with the RPM cataloger _disabled_ and pass the result to Grype. Or maybe it makes sense to use directories instead of catalogers. Will this workaround help you in the meantime?

Also, I want to link back to the existing thread at [Improvements to scanning whole machine](https://anchorecommunity.discourse.group/t/improvements-to-scanning-whole-machine/301) because these conversations are related.

---

_[View the full topic](https://anchorecommunity.discourse.group/t/show-each-cve-only-once-i-final-results/316)._
