aws / aws/containers-roadmap

Why Trivy Finds More CVEs Than Inspector?

Open
#2,648 2 comments 0 reactions 0 assignees View on GitHub
ECR Proposed
Dominant language
Shell
Stars
5.4k
Forks
334
PR merge metrics
No merged PRs in 30d

Description

Same image debian:bookworm (debian 12.10)

Result from Trivy:
Total: 94 (UNKNOWN: 1, LOW: 63, MEDIUM: 22, HIGH: 7, CRITICAL: 1)

Result from Inspector:
Critical 0 High 2 Medium 9 Low 1 Info 0

""""
debian:bookworm (debian 12.10)
==============================
Total: 94 (UNKNOWN: 1, LOW: 63, MEDIUM: 22, HIGH: 7, CRITICAL: 1)
""""

Contributor guide

Open the contributing guide

Research direction

Start by reproducing the reported scans against debian:bookworm (Debian 12.10) with Trivy and Amazon Inspector, using the versions and configuration from the issue where available. Compare the vulnerability databases, package detection, and severity mappings; done means documenting the reason for the differing counts or identifying a confirmed product issue.

Written by the indexing model from the issue text.

Assessment

Tech stack
aws, debian
Domain
cloud, security
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.