Open RichardoC opened 6 months ago
Given https://github.com/aquasecurity/trivy-db/releases/tag/v1-end-of-support I think the version 1 tag should be removed so the only option is 2 or latest. Users of the old image will fail to pull once this is done, which I think is reasonable now. We don't want folks thinking they're still getting up to date vulnerability reports when they just aren't. Discovered via https://github.com/aquasecurity/trivy-db/pkgs/container/trivy-db
It's been over 2 years since it was End of Life'd
Unfortunately it's still being downloaded over a thousand times a week https://github.com/aquasecurity/trivy-db/pkgs/container/trivy-db/12697609?tag=1
Given https://github.com/aquasecurity/trivy-db/releases/tag/v1-end-of-support I think the version 1 tag should be removed so the only option is 2 or latest. Users of the old image will fail to pull once this is done, which I think is reasonable now. We don't want folks thinking they're still getting up to date vulnerability reports when they just aren't. Discovered via https://github.com/aquasecurity/trivy-db/pkgs/container/trivy-db