Replies: 3 comments 17 replies
-
Also there are some packages that come with versionInfo as "(devel)", what could be the reason behind that? |
Beta Was this translation helpful? Give feedback.
-
Could this be the same issue I reported yesterday? #6457 |
Beta Was this translation helpful? Give feedback.
-
Hello @berke581
usr/bin/arangodb is Go binary.
So we can't detect correct version. That is why
The image If you have other questions - please send Best Regards, Dmitriy |
Beta Was this translation helpful? Give feedback.
-
Question
While generating a SBOM with spdx-json format (with the following command):
trivy image --format spdx-json --output result.json arangodb/arangodb:3.12.0
I've realised that some of the packages listed in the json does not have "versionInfo" property in them.
One of them is arangodb/arangodb:3.12.0 and its primaryPackagePurpose is CONTAINER, is this expected behavior?
(or the package named usr/bin/arangodb also doesn't have a version in it, its primaryPackagePurpose is APPLICATION)
Target
Container Image
Scanner
None
Output Format
JSON
Mode
Standalone
Operating System
Windows 10
Version
Beta Was this translation helpful? Give feedback.
All reactions