Skip to content

Analyzers showing CVEs from Base Image OR Software Dependencies #3812

Closed Answered by nscuro
larsriehn asked this question in Q&A
Discussion options

You must be logged in to vote

What version of Dependency-Track and Trivy are you running? There was a breaking change in Trivy 0.51.2's server API that caused false negatives for libraries (#3737). DT was fixed to accommodate for that in v4.11.3 (#3738).

Replies: 2 comments 1 reply

Comment options

You must be logged in to vote
1 reply
@nscuro
Comment options

Answer selected by larsriehn
Comment options

You must be logged in to vote
0 replies
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants