deepfence / deepfence/ThreatMapper

high amount of false positives detetcted

Open
#2,273 2 comments 0 reactions 1 assignee Claimed by @gnmahanth View on GitHub
bug needs-triage
Dominant language
TypeScript
Stars
5.3k
Forks
631
PR merge metrics
No merged PRs in 30d

Description

**Describe the bug**

i am currently in the evaluation of the product for our prod environment, so i did a quick deployment via docker and scanned 2 machines in my test-env.
out of 63 critical vulnerabilities a good portition seem to be false positives, almost all coming from linux-modules.
help me here if im not seeing or thinking correctly.

**To Reproduce**

-deploy docker compose
-add agents (docker/linux-baremetal)
-scan

**Screenshots**
![image](https://github.com/user-attachments/assets/a35e1159-60dc-4820-b4b0-54cd23a75844)
![image](https://github.com/user-attachments/assets/d7889562-e9b4-4f0b-8332-6ed3f84c6270)

CVE fixed in.. <-> kernel-version

**Components/Services affected**

- [?] UI/Frontend
- [?] API/Backend
- [?] Agent
- [?] Deployment/YAMLs

**Additional context**

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.