Trivy can't find vulnerable transitive dependency on an image #6191
Closed
ASarco
started this conversation in
False Detection
Replies: 2 comments 6 replies
-
Hello @ASarco Your test repository is private. Can you make it public please? Regards, Dmitriy |
Beta Was this translation helpful? Give feedback.
6 replies
-
I close this discussion. Feel free to reopen this discussion if you still have questions. Regards, Dmitiry |
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
IDs
CVE-2024-25710 CVE-2024-26308
Description
According to CVE-2024-25710 and CVE-2024-26308 , commons-compress 1.24.0 has a vulnerability. However, on a Maven Spring Boot project with modules, if this dependency is transitively added through lastest Testcontainers, Trivy image scan doesn't find it. This behaviour doesn't seem to happen on project with no modules, or when scanning the filesystem.
Reproduction Steps
Target
Container Image
Scanner
Vulnerability
Target OS
Win 10 with docker
Debug Output
Version
Checklist
-f json
that shows data sources and confirmed that the security advisory in data sources was correctBeta Was this translation helpful? Give feedback.
All reactions