Replies: 1 comment 5 replies
-
Do you mean SBOM? |
Beta Was this translation helpful? Give feedback.
5 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
Description
If I scan a Bitnami image that contains an SBOM (SPDX) file, I see a vulnerability discovered by the SPDX document, and the same vulnerability discovered by the gobinary scanning.
The vulnerability from SBOM scanning does not have a target reported (in either the table or JSON output).
Desired Behavior
I would expect 2 things:
Actual Behavior
The 2 expectations above are not met.
Reproduction Steps
docker.io/bitnami/grafana@sha256:5950f7be27595bccc83b70998bc44f85518a0c40c2c9bdeeaf6b29a15e6105f9
Target
Container Image
Scanner
Vulnerability
Output Format
Table
Mode
Standalone
Debug Output
Operating System
RHEL 8
Version
Checklist
trivy clean --all
Beta Was this translation helpful? Give feedback.
All reactions