The Fixed Version for Nginx package is older than the current one (amazon 2023.6.20241121 (Amazon Linux)) #8197
Closed
serhii-ciq
started this conversation in
Bugs
Replies: 2 comments
-
didn't investigate this just a quick note that that the fixed version includes an epoch (the |
Beta Was this translation helpful? Give feedback.
0 replies
-
Thanks @itaysk |
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
Description
Hello!
I performed a Trivy scan for my docker image and found the strange behavior for the suggested package:
It shows that fixed version 1:1.24.0-1.amzn2023.0.2 is older than my current version (1.26.2-1.amzn2023.ngx)
Could you please check it, probably this is a wrong suggestion.
Desired Behavior
The fixed version should be newer than the vulnerable version
Actual Behavior
The fixed version is older than the vulnerable version
Reproduction Steps
Target
Container Image
Scanner
Vulnerability
Output Format
JSON
Mode
None
Debug Output
Checklist
trivy clean --all
Beta Was this translation helpful? Give feedback.
All reactions