Skip to content

bug(vex): Trivy incorrectly suppresses vulnerabilities if the report contains orphan packages. #9526

@DmitriyLewen

Description

@DmitriyLewen

Description

There are cases when a Trivy SBOM report contains an orphan package (see #9011).
This is related to an infinite loop in dependencies, e.g.:
e.g.

pkgA -> pkgB
pkbB -> pkbA

Therefore, for such packages, we cannot reach the root of the tree and must mark them as affected (!notAffected).

return false

The vex package should handle such cases, similar to how it handles packages without a parent.

Metadata

Metadata

Assignees

Labels

No labels
No labels

Type

No type

Projects

Status

No status

Milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions