Different result for VEX between SBOM and image scanning #10467
AugustusKling
started this conversation in
Bugs
Replies: 0 comments
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
-
Description
I try to use a VEX file to exclude findings. This works when scanning a Docker image but not when producing an SBOM and then scanning the SBOM. This difference is there when the VEX contains a statement with subcomponents.
Desired Behavior
No difference in output between scanning an image vs producing an SBOM from the image and then scanning the SBOM.
Actual Behavior
Statement in VEX file is ignored when scanning SBOM.
Reproduction Steps
Target
Container Image
Scanner
Vulnerability
Output Format
None
Mode
Standalone
Debug Output
Operating System
Windows 11 Enterprise
Version
Checklist
trivy clean --allBeta Was this translation helpful? Give feedback.
All reactions