-
Notifications
You must be signed in to change notification settings - Fork 2.5k
Issues: aquasecurity/trivy
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Author
Label
Projects
Milestones
Assignee
Sort
Issues list
refactor(db): change logic to detect wrong DB
#8864
opened May 13, 2025 by
DmitriyLewen
Loading…
3 of 6 tasks
feat(license): improve work with custom classification of licenses from config file
#8861
opened May 13, 2025 by
DmitriyLewen
Loading…
3 of 6 tasks
enhancement(license): improve work with custom classification of licenses from config file
scan/license
Issues relating to license scanning
bug(sbom): Categorizes issue or PR as related to a bug.
scan/sbom
Issues relating to SBOM
sbom
mode should support --distro
flag
kind/bug
bug(report): Trivy panics when converting json report without Categorizes issue or PR as related to a bug.
Packages
to table report with summary table
kind/bug
#8622
opened Mar 27, 2025 by
DmitriyLewen
fix(report): don't panic when report contains vulns, but doesn't contain packages for
table
format
#8549
opened Mar 14, 2025 by
DmitriyLewen
Loading…
2 of 6 tasks
bug(sbom): Trivy only checks parents from the current result when plotting the dependency graph
kind/bug
Categorizes issue or PR as related to a bug.
scan/sbom
Issues relating to SBOM
#8516
opened Mar 10, 2025 by
DmitriyLewen
fix(flag): resolve env's from config file for
string
and []string
flags
#8437
opened Feb 24, 2025 by
DmitriyLewen
•
Draft
8 tasks
feat(flag): resolve env's from config file
kind/feature
Categorizes issue or PR as related to a new feature.
#8436
opened Feb 24, 2025 by
DmitriyLewen
feat: add fields for Categorizes issue or PR as related to a new feature.
scan/vulnerability
Issues relating to vulnerability scanning
target/container-image
Issues relating to container image scanning
json
and SBOM
formats with info that Trivy doesn't support OS
kind/feature
#8256
opened Jan 20, 2025 by
DmitriyLewen
enhancement(cyclonedx): use Issues relating to SBOM
Compositions
field for dependencies with unknown
relationships
scan/sbom
#8157
opened Dec 23, 2024 by
DmitriyLewen
refactor: use UUID/hash for Packages IDs from
pom.xml
files.
#7879
opened Nov 6, 2024 by
DmitriyLewen
Loading…
4 of 7 tasks
bug(sbom): Duplicate SBOM packages for multi-module pom.xml files
kind/bug
Categorizes issue or PR as related to a bug.
feat(java): add support of
test
scope for pom.xml
files
#7486
opened Sep 11, 2024 by
DmitriyLewen
•
Draft
3 of 7 tasks
refactor: include/exclude dev deps in analyzers
#7484
opened Sep 11, 2024 by
DmitriyLewen
Loading…
3 of 6 tasks
feat(report): add
Supported
field for json
and SBOM
formats
#7378
opened Aug 23, 2024 by
DmitriyLewen
Loading…
2 of 6 tasks
fix(sbom): detect OS from Denotes an issue or PR has remained open with no activity and will be auto-closed.
purl
if OS component not found
lifecycle/stale
#7101
opened Jul 5, 2024 by
DmitriyLewen
Loading…
3 of 6 tasks
fix(sbom): detect OS from Categorizes issue or PR as related to a bug.
purl
if OS component not found
kind/bug
#7100
opened Jul 5, 2024 by
DmitriyLewen
fix(sbom): detect main OS and ignore pkgs for other OSes
#6907
opened Jun 11, 2024 by
DmitriyLewen
Loading…
3 of 6 tasks
feat(oci): add support OCI tarballs
kind/feature
Categorizes issue or PR as related to a new feature.
#5775
opened Dec 12, 2023 by
DmitriyLewen
tar archive may not be scanned depending on how it was created
kind/bug
Categorizes issue or PR as related to a bug.
priority/backlog
Higher priority than priority/awaiting-more-evidence.
#3080
opened Oct 26, 2022 by
raesene
Trivy warns "failed to get the vulnerability" about a rejected CVE, CVE-2021-20095
kind/bug
Categorizes issue or PR as related to a bug.
priority/backlog
Higher priority than priority/awaiting-more-evidence.
#2623
opened Jul 29, 2022 by
hlein
ProTip!
Add no:assignee to see everything that’s not assigned.