-
Notifications
You must be signed in to change notification settings - Fork 2.6k
aquasecurity trivy Discussions
Sort by:
Latest activity
Categories, most helpful, and community links
Categories
Community links
Discussions
-
You must be logged in to vote 🐛 Trivy rootfs does not detect CVE in .jar when version has a suffix
kind/bugCategorizes issue or PR as related to a bug. -
You must be logged in to vote 💡 Inline Ignore comment not working
kind/featureCategorizes issue or PR as related to a new feature. -
You must be logged in to vote 🐛 Unofficial License Names in CycloneDX SBOMs
kind/bugCategorizes issue or PR as related to a bug. -
You must be logged in to vote 🔎 -
You must be logged in to vote 🐛 fix(license): Incorrect license suppression for combined licenses with --ignored-licenses
kind/bugCategorizes issue or PR as related to a bug. -
You must be logged in to vote 🙏 Trivy not detecting vulnerabilties
triage/supportIndicates an issue that is a support question. scan/vulnerabilityIssues relating to vulnerability scanning -
You must be logged in to vote 🙏 False positive: GHSA-fh5r-crhr-qrrq (CVE-2025-23184) cxf core 3.5.8.redhat-00001
triage/supportIndicates an issue that is a support question. scan/vulnerabilityIssues relating to vulnerability scanning -
You must be logged in to vote 🙏 How do I find issues I need to patch?
triage/supportIndicates an issue that is a support question. -
You must be logged in to vote 📢 -
You must be logged in to vote 💡 Support trivy version --server to return server version and vulnerability DB metadata
kind/featureCategorizes issue or PR as related to a new feature. -
You must be logged in to vote 👨💻 -
You must be logged in to vote 💡 Add license scanning for Ruby filesystem
kind/featureCategorizes issue or PR as related to a new feature. target/filesystemIssues relating to filesystem scanning scan/licenseIssues relating to license scanning -
You must be logged in to vote 🐛 deb Built-Using field is not parsed
kind/bugCategorizes issue or PR as related to a bug. -
You must be logged in to vote 🐛 bug(bitnami): Go CVEs are reported twice
kind/bugCategorizes issue or PR as related to a bug. -
You must be logged in to vote 🙏 Image Vulnerability Scans. How to exclude known vulnerabilities in approved base image
triage/supportIndicates an issue that is a support question. -
You must be logged in to vote 🐛 Trivy Filesystem Scan fails running on Docker Container on MacOS
kind/bugCategorizes issue or PR as related to a bug. -
You must be logged in to vote 🔎 -
You must be logged in to vote 💡 priorityClassName
kind/featureCategorizes issue or PR as related to a new feature. -
You must be logged in to vote 🙏 Secure Python Package Delivery with an Internal Proxy and Trivy?
triage/supportIndicates an issue that is a support question. -
You must be logged in to vote 📢 BREAKING: Deprecating
kind/deprecationid
andlong_id
for misconfiguration checksCategorizes issue or PR as related to a feature/enhancement marked for deprecation. -
You must be logged in to vote 💡 feat: Allow Trivy server to customize the database reload interval
kind/featureCategorizes issue or PR as related to a new feature. scan/vulnerabilityIssues relating to vulnerability scanning -
You must be logged in to vote 💡 Use EUVD database
kind/featureCategorizes issue or PR as related to a new feature. scan/vulnerabilityIssues relating to vulnerability scanning -
You must be logged in to vote 💡 trivy compliance report template
kind/featureCategorizes issue or PR as related to a new feature. scan/misconfigurationIssues relating to misconfiguration scanning target/container-imageIssues relating to container image scanning -
You must be logged in to vote 💡 Prevent storing secrets in state by flagging these and where possible suggest solutions like ephemeral resources over data sources and write-only attributes over normal attributes
kind/featureCategorizes issue or PR as related to a new feature. scan/secretIssues relating to secret scanning target/cloudIssues relating to cloud account scanning -
You must be logged in to vote 🐛 0.63.0 version check reporting older version is available
kind/bugCategorizes issue or PR as related to a bug.