Skip to content

Trivy doesn't update vulnerability after updating package manually #7359

Closed Answered by DmitriyLewen
juyoungkimthedev asked this question in Q&A
Discussion options

You must be logged in to vote

Hello @juyoungkimthedev
Thanks for your report!

We use separate advisory lists for each Debian release.
But we have no way to detect this installed version from another release.

Debian 10 does not have fixed version for CVE-2024-42154.
That's why Trivy still marks this package as vulnerable.

Replies: 1 comment 3 replies

Comment options

You must be logged in to vote
3 replies
@juyoungkimthedev
Comment options

@DmitriyLewen
Comment options

@juyoungkimthedev
Comment options

Answer selected by juyoungkimthedev
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
triage/support Indicates an issue that is a support question. scan/vulnerability Issues relating to vulnerability scanning
2 participants