anchore / anchore-engine

A service that analyzes docker images and scans for vulnerabilities
Apache License 2.0
1.57k stars 273 forks source link

False positive CVE-2021-27498 reported for npm opener 1.5.2 #1389

Open navzen2000 opened 1 year ago

navzen2000 commented 1 year ago

Is this a request for help?:


Is this a BUG REPORT or a FEATURE REQUEST? (choose one): BUG

Version of Anchore Engine and Anchore CLI if applicable: 1.1.0

What happened: CVE-2021-27498,CVE-2021-27478,CVE-2021-27500,CVE-2021-27482 got reported for npm opener package

What did you expect to happen:

Any relevant log output from /var/log/anchore:

What docker images are you using:

How to reproduce the issue:

Anything else we need to know: