Skip to content
Discussion options

You must be logged in to vote

Hello @ckcr4lyf
Thanks for your report.

Just like Alpine stores its advisories separately for each release, Trivy also uses a dedicated vulnerability database per Alpine version.

For Alpine 3.20 the fixed version is 74.2-r1,
while for Alpine 3.23 the fixed version is 76.1-r1.

Therefore, when you scan version 74.2-r1, Trivy marks this package as vulnerable only for Alpine 3.23, because in 3.23 the fixed version is higher (76.1-r1), but in 3.20 it is already fixed.

Links:

Regards, Dmitriy

Replies: 1 comment 1 reply

Comment options

You must be logged in to vote
1 reply
@ckcr4lyf
Comment options

Answer selected by ckcr4lyf
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
triage/support Indicates an issue that is a support question. scan/vulnerability Issues relating to vulnerability scanning
2 participants