trivy k8s option --scaners vuln not displaying report/scan for different components accurately #5819
Replies: 3 comments 5 replies
-
@chen-keinan Can you please take a look? |
Beta Was this translation helpful? Give feedback.
-
Now, We would go with Chen's suggestion for simplicity. |
Beta Was this translation helpful? Give feedback.
-
Yes that all makes sense to me. Thank you for sharing the diagram. However, @chen-keinan separately, there seems to be a bug if |
Beta Was this translation helpful? Give feedback.
-
Description
When performing the following scan:
It does not make a difference whether
--components
isworkload
orinfra
, the output of the report is always going to be the workload assessment but just for the infrastructure components:Desired Behavior
I would expect there to be a difference in the vulnerability scans for the workloads and for the infrastructure. For instance, when I perform a K8s cluster scan but don't specify the vulnerability scanner, then there is a big difference between the
infra
scan and theworkload
scan.Infra:
Workloard part:
Actual Behavior
As described before
Reproduction Steps
Target
Kubernetes
Scanner
Vulnerability
Output Format
Table
Mode
Standalone
Debug Output
Operating System
macOS
Version
Checklist
trivy image --reset
Beta Was this translation helpful? Give feedback.
All reactions