Replies: 5 comments 37 replies
-
Hi @gwitsch ! We have encountered the same thing at CI and are still looking into the problem. |
Beta Was this translation helpful? Give feedback.
-
Please see https://aquasecurity.github.io/trivy/v0.55/docs/references/troubleshooting/#github-rate-limiting |
Beta Was this translation helpful? Give feedback.
-
We published trivy-db in Amazon ECR Public Gallery as well as GHCR. The following should work now. We'll update the documentation tomorrow.
|
Beta Was this translation helpful? Give feedback.
-
I've not been able to get a successful Trivy run in GitLab for the last few hours due to this issue. We've seen it on and off in the past but all of our installs fail 100% now. This is causing our pipelines to fail so we can no longer merge code.
|
Beta Was this translation helpful? Give feedback.
-
I found an option to create a local cache by setting the environment variable TRIVY_CACHE_DIR= and using the command trivy --download-db-only. It downloads the database to the specified path, and when scanning images, it won't connect to https://ghcr.io/v2/aquasecurity/trivy-db/manifests/2. I think this could solve the issue. Doc : https://aquasecurity.github.io/trivy/v0.56/docs/advanced/air-gap/#populating-the-trivy-cache |
Beta Was this translation helpful? Give feedback.
-
Question
Hello,
recently trivy is having issues updating the database before scanning container images.
To isolate the problem, I have introduced a separate update task which runs the update-only commands.
The problem only occurs at our nightly build pipeline run betwenn 8pm - 11pm.
Here is the update commands output:
From my point of view, it looks like it's a problem related to the Github container registry. I guess there is some kind of DDoS protection in place.
Has anyone already faced the same issue? Or already found a solution?
Best regards,
Gotthard
Target
Container Image
Scanner
None
Output Format
None
Mode
Standalone
Operating System
Ubuntu
Version
Beta Was this translation helpful? Give feedback.
All reactions