You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
But for example, CVE-2024-45410 (9.8) isn't detected.
Next, I did download the database used by grype, and the CVE is there.
My first guess was that grype was only analyzing dependencies, but not the software itself, so I ran syft to check the detected SBOM, but traefik was correctly detected:
willmurphyscode
changed the title
Not detecting vulnerability of a docker image whereas available in database
correctly identify version of traefik binaries
Oct 15, 2024
What happened:
I wanted to try if
grype
was able to correctly detect CVE in my running images, so I tried the following :But for example, CVE-2024-45410 (9.8) isn't detected.
Next, I did download the database used by
grype
, and the CVE is there.My first guess was that
grype
was only analyzing dependencies, but not the software itself, so I ransyft
to check the detected SBOM, but traefik was correctly detected:The text was updated successfully, but these errors were encountered: