Repository navigation
aquasecurity trivy Discussions
Pinned Discussions
Sort by:
Latest activity
Categories, most helpful, and community links
Categories
Community links
Discussions
-
You must be logged in to vote π Trivy does not correctly handle golang pseudo-versions.
kind/bugCategorizes issue or PR as related to a bug. -
You must be logged in to vote π‘ -
You must be logged in to vote π Inconsistent vulnerability data for Ubuntu
scan/vulnerabilityIssues relating to vulnerability scanning -
You must be logged in to vote π‘ SPDX 3?
kind/featureCategorizes issue or PR as related to a new feature. scan/vulnerabilityIssues relating to vulnerability scanning -
You must be logged in to vote π‘ Support
kind/featuretopologySpreadConstraintsin the Trivy Helm chartCategorizes issue or PR as related to a new feature. target/kubernetesIssues relating to kubernetes cluster scanning -
You must be logged in to vote π gomod fs scanner reports false positive vulnerabilities when scanning Go module cache directories (.cache/pkg/mod/)
scan/vulnerabilityIssues relating to vulnerability scanning target/filesystemIssues relating to filesystem scanning target/repositoryIssues relating to VCS repository scanning -
You must be logged in to vote π -
You must be logged in to vote π CloudFormation: API Gateway checks miss resources and stages, and findings can vary between scans
scan/misconfigurationIssues relating to misconfiguration scanning -
You must be logged in to vote π¨βπ» -
You must be logged in to vote π VEX not_affected statements are ignored for OS packages whose dependency path contains a cycle (e.g. git <-> perl-Git)
kind/bugCategorizes issue or PR as related to a bug. -
You must be logged in to vote π Non-deterministic purl for Wolfi packages discovered via
kind/bug/var/lib/db/sbom(two apk components per SPDX document)Categorizes issue or PR as related to a bug. -
You must be logged in to vote π Encountering 429 on Maven Central when analyzing Gradle project
triage/supportIndicates an issue that is a support question. -
You must be logged in to vote π
kind/bug--vexrejects valid CSAF 2.0 documents that declareproduct_tree.product_groupsCategorizes issue or PR as related to a bug. -
You must be logged in to vote π -
You must be logged in to vote π Request to Discuss Weaknesses/Vulnerabilities with Affected Products
kind/bugCategorizes issue or PR as related to a bug. -
You must be logged in to vote π -
You must be logged in to vote π -
You must be logged in to vote π¨βπ» -
You must be logged in to vote π -
You must be logged in to vote π‘ Allow choosing where --generate-default-config writes the file
kind/featureCategorizes issue or PR as related to a new feature. -
You must be logged in to vote π‘ [Feature Request] CLI flag to disable remote module downloads during IaC scanning
kind/featureCategorizes issue or PR as related to a new feature. scan/misconfigurationIssues relating to misconfiguration scanning -
You must be logged in to vote π -
You must be logged in to vote π’ -
You must be logged in to vote π¨βπ» -
You must be logged in to vote π‘ Rescoring of vulnerabilities (severity modification) with VEX
kind/featureCategorizes issue or PR as related to a new feature. scan/vulnerabilityIssues relating to vulnerability scanning