Replies: 2 comments
-
|
Anyone? |
Beta Was this translation helpful? Give feedback.
0 replies
-
Workaround: Remove all components, this purges all vulnerabilities. Then upload the sbom again to restore the components and trigger a new analysis. |
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
-
We use the Trivy analyzer and have imported the SBOM's with "Ignore unfixed vulnerabilities" switched off.
I now set the switch to "Ignore unfixed vulnerabilities", and nothing changed. I expected that during the next daily "Portfolio vulnerability analysis" the number of CVE's would drop and only Trivy CVE's with an existing fix are shown. But this is not the case. All CVE's remain.
Is this the intended behaviour?
Can I achieve a new (clear) CVE evaluation in any way?
Beta Was this translation helpful? Give feedback.
All reactions