Find vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code repositories, clouds and more
23.79k
stars
2.34k
forks
source link
bug(k8s): inconsistent results from summary and all report on k8s workload #7937
Closed
afdesk closed 2 days ago
Description
There are cases when
summary
report doesn't contain information about vulnerabilities.Reason
For consolidated report Trivy looks for vulns and secrets only in the first result. The second and next results are skipped now.
https://github.com/aquasecurity/trivy/blob/main/pkg/k8s/report/report.go#L282-L283
Reproduction steps:
pod.yaml
:Discussed in https://github.com/aquasecurity/trivy/discussions/7927