anchore / scan-action

Anchore container analysis and scan provided as a GitHub Action
MIT License
204 stars 74 forks source link

False positives? #242

Open michelesr opened 11 months ago

michelesr commented 11 months ago

Have a look at https://github.com/citizensadvice/fluentd-docker/security/code-scanning/30, the CVE is about busybox < 1.35 , and busybox is on 1.35.0-r29 (and so is ssl_client) ... interestingly when running grype on an image built in the same way locally, I don't get this issue.