Replies: 1 comment
-
|
Duplicate of #9446 |
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
-
Description
We have Envoy Proxy Gateway deployed to our cluster. We deploy it using the official helm chart. The current version is 1.7.0. When running
trivy kubernetes --report all --timeout 60m --include-namespaces networking,trivymisidentifies its version asv0.0.0-20260205163311-da2aac967d53, instead of `1.7.0:v1.7.0was released on 2026.02.05 and its commit hash isda2aac967d53.Desired Behavior
Correctly identified deployment version :-)
Actual Behavior
Envoy Proxy Gateway version identified as
v0.0.0-20260205163311-da2aac967d53, reporting a false positive with 2 high and 1 medium CVE.Reproduction Steps
Target
None
Scanner
Vulnerability
Output Format
Table
Mode
Standalone
Debug Output
Operating System
Windows 10 Pro
Version
Checklist
trivy clean --allBeta Was this translation helpful? Give feedback.
All reactions