Why Trivy Finds More CVEs Than Inspector?
- Dominant language
- Shell
- Stars
- 5.4k
- Forks
- 334
- PR merge metrics
- No merged PRs in 30d
Description
Same image debian:bookworm (debian 12.10)
Result from Trivy:
Total: 94 (UNKNOWN: 1, LOW: 63, MEDIUM: 22, HIGH: 7, CRITICAL: 1)
Result from Inspector:
Critical 0 High 2 Medium 9 Low 1 Info 0
""""
debian:bookworm (debian 12.10)
==============================
Total: 94 (UNKNOWN: 1, LOW: 63, MEDIUM: 22, HIGH: 7, CRITICAL: 1)
""""
Contributor guide
Research direction
Start by reproducing the reported scans against debian:bookworm (Debian 12.10) with Trivy and Amazon Inspector, using the versions and configuration from the issue where available. Compare the vulnerability databases, package detection, and severity mappings; done means documenting the reason for the differing counts or identifying a confirmed product issue.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- aws, debian
- Domain
- cloud, security
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 35/100