Closed vasiliy-ul closed 2 years ago
Hello @vasiliy-ul Thanks for your report!
I created #3199 with fix this problem. When it is merged - we will include this fix in the next release.
Regards, Dmitriy
Hi @DmitriyLewen , thank you for the quick fix :+1:
Checklist
-f json
that shows data sources and make sure that the security advisory is correct.Description
Trivy reports wrong
Fixed Version
forqemu-ipxe
,qemu-seabios
andqemu-vgabios
:The Fixed Version suggested by Trivy
6.2.0-150400.37.5.3
seems to be taken from the main packageqemu
. Though the subpackagesqemu-ipxe
,qemu-seabios
andqemu-vgabios
have a different versioning scheme.The CVRF data (cvrf-suse-su-2022_2260-1.xml and cvrf-suse-su-2022_3795-1.xml) suggests the correct versioning:
JSON Output of run with
-debug
:Output of
trivy -v
:Additional details (base image name, container registry info...):
Container image: registry.suse.com/suse/sles/15.4/virt-launcher:0.54.0-150400.3.5.1