Replies: 5 comments 12 replies
-
|
@afdesk could you take a look? We might have to update the IDs. |
Beta Was this translation helpful? Give feedback.
-
|
@sfozz thanks for the report! where did you get this list? maybe I missed something. thanks |
Beta Was this translation helpful? Give feedback.
-
|
Yeah so in your screen shot of the browser the ID matches with the one that I shared, but that doesn't match with the PDF of that benchmark or the one on browser from IBM (The screenshot that I shared) Interesting that your trivy output is correct to the ID from the PDF from CIS CAT, and the screen shot that I shared. I wonder if there are some sources that are off by one and some that are not??? Where do the IDs that trivy outputs coming from, and what is the point of truth? |
Beta Was this translation helpful? Give feedback.
-
|
Beta Was this translation helpful? Give feedback.
-
|
I think I've figured where the confusion comes from. CIS Kubernetes Benchmark v1.11.1 was published Apr 28th 2025 where as CIS Kubernetes V1.23 Benchmark v1.0.1 was published May 26th 2022 I think that historically there were versions of the benchmark that were created to match the k8s version. and looking at the intended audience in v1.11.1 it states that it is for k8s v1.29 to v1.32. But in v1.23 v1.0.1 it is specifically for k8s v1.23. And there is a ticket for this in the CIS Workbench |
Beta Was this translation helpful? Give feedback.



Uh oh!
There was an error while loading. Please reload this page.
-
Description
The reference IDs in the the summary report don't align with the same IDs in the CIS Benchmark. Looking at the output report the 5.6 group of references in the benchmark are reported as 5.7 in the trivy report
Desired Behavior
The last few items in the report should cross reference correctly with the benchmark
Actual Behavior
The appear like the following in the report
Reproduction Steps
Target
Kubernetes
Scanner
Misconfiguration
Output Format
Table
Mode
Standalone
Debug Output
Operating System
Debian GNU/Linux 13 (trixie)
Version
Checklist
trivy clean --allBeta Was this translation helpful? Give feedback.
All reactions