You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Hi,
I found out that latest score 10 vulnerability is not detect by Trivy, see details here aquasecurity/trivy#9595 .
It seems that one of the solution might be to distribute SBOM CycloneDX JSON files in one of the layers.
It is because Redis binary cannot be scanned for dependencies etc.
Would you consider support this?
Thank you
Ivos
From Trivy source-code (and docs):
Files with suffix *.cdx and *.cdx.json somewhere at filesystem like /sbom/my-sbom-1.cdx.json.