-
Notifications
You must be signed in to change notification settings - Fork 2.6k
Issues: aquasecurity/trivy
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Author
Label
Projects
Milestones
Assignee
Sort
Issues list
docs(misconf): improve documentation and examples for AVD-AWS-0132
kind/documentation
Categorizes issue or PR as related to documentation.
scan/misconfiguration
Issues relating to misconfiguration scanning
feat(misconf): normalize CreatedBy strings for COPY and ADD instructions for podman (buildah) images
kind/feature
Categorizes issue or PR as related to a new feature.
scan/misconfiguration
Issues relating to misconfiguration scanning
#8952
opened May 30, 2025 by
nikpivkin
0.63.0 version check for config command missing flags
kind/bug
Categorizes issue or PR as related to a bug.
#8950
opened May 30, 2025 by
owenrumney
fix(misconf): add support for workload_metadata_config.mode values in AVD-GCP-0057
kind/bug
Categorizes issue or PR as related to a bug.
scan/misconfiguration
Issues relating to misconfiguration scanning
#8940
opened May 29, 2025 by
nikpivkin
bug(vex): Trivy doesn't support auth for OCI images from private registries
kind/bug
Categorizes issue or PR as related to a bug.
#8916
opened May 26, 2025 by
DmitriyLewen
bug(misconf): Trivy does not skip AVD-DS-0016 when scanning docker image history
kind/bug
Categorizes issue or PR as related to a bug.
scan/misconfiguration
Issues relating to misconfiguration scanning
feat(misconf): Add short_code for checks into AVD
kind/documentation
Categorizes issue or PR as related to documentation.
kind/feature
Categorizes issue or PR as related to a new feature.
scan/misconfiguration
Issues relating to misconfiguration scanning
bug(misconf): Handle resources where pattern evaluation can return an unknown value
kind/bug
Categorizes issue or PR as related to a bug.
fix(deps): treat packages with same version but different dependencies as separate packages
kind/bug
Categorizes issue or PR as related to a bug.
#8776
opened Apr 25, 2025 by
knqyf263
feat(misconf): Adding support for detecting misconfigurations in docker-compose.yml natively
kind/feature
Categorizes issue or PR as related to a new feature.
scan/misconfiguration
Issues relating to misconfiguration scanning
#8729
opened Apr 12, 2025 by
simar7
feat(checks): Add checks to detect suspicious Kubernetes URL annotations
kind/feature
Categorizes issue or PR as related to a new feature.
target/kubernetes
Issues relating to kubernetes cluster scanning
#8672
opened Apr 3, 2025 by
simar7
bug: trivy convert always filters non-failures
kind/bug
Categorizes issue or PR as related to a bug.
bug(sbom): Categorizes issue or PR as related to a bug.
scan/sbom
Issues relating to SBOM
sbom
mode should support --distro
flag
kind/bug
bug(report): Trivy panics when converting json report without Categorizes issue or PR as related to a bug.
Packages
to table report with summary table
kind/bug
#8622
opened Mar 27, 2025 by
DmitriyLewen
bug(sbom): Trivy only checks parents from the current result when plotting the dependency graph
kind/bug
Categorizes issue or PR as related to a bug.
scan/sbom
Issues relating to SBOM
#8516
opened Mar 10, 2025 by
DmitriyLewen
docs: add explanation for how to use non-system certificates
good first issue
Denotes an issue ready for a new contributor, according to the "help wanted" guidelines.
kind/documentation
Categorizes issue or PR as related to documentation.
#8440
opened Feb 24, 2025 by
knqyf263
feat(flag): resolve env's from config file
kind/feature
Categorizes issue or PR as related to a new feature.
#8436
opened Feb 24, 2025 by
DmitriyLewen
feat(opensuse): add Denotes an issue that needs help from a contributor. Must meet "help wanted" guidelines.
scan/vulnerability
Issues relating to vulnerability scanning
MicroOS
and Leap Micro
support
help wanted
#8409
opened Feb 17, 2025 by
DmitriyLewen
feat: add fields for Categorizes issue or PR as related to a new feature.
scan/vulnerability
Issues relating to vulnerability scanning
target/container-image
Issues relating to container image scanning
json
and SBOM
formats with info that Trivy doesn't support OS
kind/feature
#8256
opened Jan 20, 2025 by
DmitriyLewen
enhancement(cyclonedx): use Issues relating to SBOM
Compositions
field for dependencies with unknown
relationships
scan/sbom
#8157
opened Dec 23, 2024 by
DmitriyLewen
fix(sarif): check url before converting to string
kind/bug
Categorizes issue or PR as related to a bug.
#8154
opened Dec 21, 2024 by
nikpivkin
2 tasks done
bug(k8s): Trivy gets stuck when scanning a cluster with taints on nodes
bug
target/kubernetes
Issues relating to kubernetes cluster scanning
#8087
opened Dec 12, 2024 by
afdesk
bug(secret): false positive for Categorizes issue or PR as related to a bug.
scan/secret
Issues relating to secret scanning
gcp-service-account
kind/bug
#8079
opened Dec 11, 2024 by
nikpivkin
2 tasks done
Previous Next
ProTip!
Adding no:label will show everything without a label.