False possitive on different frameworks #7142
Replies: 3 comments 6 replies
-
Hello @msmolka Unfortunately, GitHub advisory database (we use this db for .NET vulns (https://aquasecurity.github.io/trivy/v0.53/docs/scanner/vulnerability/#data-sources_1)) doesn't contain field for version of .NET (only advisory So we have no way to get this information (there are no rules for getting detailed information, and we can't get the .net version from this field). You can write module or use VEX to skip this CVE for your case. Regards, Dmitriy |
Beta Was this translation helpful? Give feedback.
-
But you have ranges here: |
Beta Was this translation helpful? Give feedback.
-
I'm using devOps trivy. It looks it is a bit outdated. Will try new version first, sorry for inconvenience, I need to double check env then |
Beta Was this translation helpful? Give feedback.
-
IDs
CVE-2024-30105
Description
Based on information: dotnet/announcements#315
this is only affecting .NET 8
I have multitarget project with different version of related packages: packages.lock.json
Error is reported for not affected .net frameworks
Reproduction Steps
Added false positive packages file
Target
Container Image
Scanner
Vulnerability
Target OS
Ubuntu
Debug Output
Version
Checklist
-f json
that shows data sources and confirmed that the security advisory in data sources was correctBeta Was this translation helpful? Give feedback.
All reactions