Skip to content

CVEs in Busybox v. 1.36.1 are not being detected #6132

Closed Answered by DmitriyLewen
mike-miller-ct asked this question in Q&A
Discussion options

You must be logged in to vote

Hello @mike-miller-ct
Thanks for your interest to Trivy!

We use Alpine security database to get advisories for Alpine - https://aquasecurity.github.io/trivy/v0.49/docs/scanner/vulnerability/#data-sources
The Alpine team did not add these CVEs (perhaps these CVEs did not affect their versions of busibox).

Regards, Dmitriy

Replies: 1 comment

Comment options

You must be logged in to vote
0 replies
Answer selected by mike-miller-ct
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
triage/support Indicates an issue that is a support question. scan/vulnerability Issues relating to vulnerability scanning
2 participants