AVD-KSV-0013 containers should specify an image tag - false positive #9327
Closed
huornlmj
started this conversation in
False Detection
Replies: 1 comment
-
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
-
IDs
AVD-KSV-0013
Description
A false positive is found by Trivy in misconfiguration scanning mode.
Trivy output:
Reproduction Steps
1. Scan https://github.com/intel/intent-driven-orchestration/blob/9f37fe0552245f1c8b41285aed61696c3b375ceb/artefacts/deploy/manifest.yaml#L202 2. Observe that a pinned version is used. 3. Observe the false positive result from Trivy.Target
Kubernetes
Scanner
Misconfiguration
Target OS
N/A
Debug Output
Version
Checklist
-f jsonthat shows data sources and confirmed that the security advisory in data sources was correctBeta Was this translation helpful? Give feedback.
All reactions