Skip to content

False negatives on php:8.1.0-fpm, php:8.2.5-fpm, ... #7958

Closed Answered by DmitriyLewen
valentijnscholten asked this question in Q&A
Discussion options

You must be logged in to vote

Hello @valentijnscholten
Thanks for your report!

Trivy only detects Go and Rust binaries (cargo-auditable).
If php is not installed from the OS package manager (apt/dpkg for this image) - Trivy can't detect php package and vulnerabilities for it.
See https://trivy.dev/v0.57/docs/coverage/ and https://trivy.dev/v0.57/docs/coverage/language/#supported-languages and for more details.

Regards, Dmitriy

Replies: 1 comment 1 reply

Comment options

You must be logged in to vote
1 reply
@valentijnscholten
Comment options

Answer selected by valentijnscholten
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
triage/support Indicates an issue that is a support question. scan/vulnerability Issues relating to vulnerability scanning
2 participants