Replies: 2 comments 5 replies
-
Hello @RichieB2B CycloneDX docs doesn't have info that |
Beta Was this translation helpful? Give feedback.
3 replies
-
I still believe it's Ubuntu's problem, but it looks like we should fix it on our end. |
Beta Was this translation helpful? Give feedback.
2 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
Description
When I run trivy with
--format cyclonedx
it produces invalid CycloneDX for Debian CVE-2023-31484. The " (2.35-TRIAL)" is appended to the URL making it invalid.Desired Behavior
I expect trivy to parse this URL as:
Actual Behavior
It is actually parsed as:
This is an invalid URL, causing parsing of the CycloneDX JSON to fail in our security tooling.
Reproduction Steps
Target
Container Image
Scanner
Vulnerability
Output Format
CycloneDX
Mode
Standalone
Debug Output
Operating System
Ubuntu 22
Version
Checklist
trivy image --reset
Beta Was this translation helpful? Give feedback.
All reactions