Latest checks database failing for valid Dockerfiles: Secrets passed via build-args
or envs or copied secret files
#7830
Closed
peetw
started this conversation in
False Detection
Replies: 1 comment
-
Please see #7828 (comment) |
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
IDs
AVD-DS-0031
Description
After the latest
trivy-checks
package was released earlier this morning (version 1.2), we have noticed a large number of trivy Dockerfile checks failing with the following error:This occurs even for the most minimal Dockerfile possible (see repro steps below).
Passing the
--skip-check-update
option totrivy
resolves the issue, but doesn't seem to be a long-term solution?Reproduction Steps
Target
Filesystem
Scanner
Misconfiguration
Target OS
No response
Debug Output
Version
Checklist
-f json
that shows data sources and confirmed that the security advisory in data sources was correctBeta Was this translation helpful? Give feedback.
All reactions