Vulnerabilities scan with Trivy #1350
thelittlefireman
started this conversation in
Ideas
Replies: 1 comment
-
This doesn't seem particularly valuable. Each bitwarden_rs image build generally uses the latest base image available and installs the latest packages available at that time, so that's pretty much the best that can be done, short of rebuilding the images on each base image update. This tool also has a ton of false positives... |
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
Hi,
could it be possible to add trivy scan on CI on docker image ?
The image base on alpine is safe, but on debian (latest) contains lots of CVE :
alpine result :
debian result :
Beta Was this translation helpful? Give feedback.
All reactions