Replies: 2 comments 6 replies
-
|
Hi @acdha ! Thanks for the report Track #10110 |
Beta Was this translation helpful? Give feedback.
0 replies
-
|
Release a new trivy-checks bundle which will mitigate this https://github.com/aquasecurity/trivy-checks/releases/tag/v2.1.1 |
Beta Was this translation helpful? Give feedback.
6 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
-
Description
Prior to 0.69.0, the check IDs were things like
avd-aws-0053. Those are used in ignore rules and also in the links emitted by the scanner for each finding.With 0.69.0, presumably due to the switch to the new checks bundle, all of the IDs changed to e.g.
aws-0053. This causes all existing ignore rules to be ignored because the IDs don't match and also appears to have broken all of the links to avd.aquasec.com because the pages are still published under the old IDs. For example, Trivy 0.69.0 will link to https://avd.aquasec.com/misconfig/aws-0053, which returns a 404, rather than https://avd.aquasec.com/misconfig/avd-aws-0053Desired Behavior
Ideally the old IDs would either continue working or Trivy would have an easy command-line option to migrate the ignores.
The report links should either be updated to use the old IDs or the pages republished/redirected on the avd.aquasec.com server.
Actual Behavior
Only the new IDs are used.
Reproduction Steps
I used the official containers to simplify reproduction:
The Terraform code in question:
Other resources covered by rules in a
.trivyignore.yamlfile were also affected.Target
Filesystem
Scanner
Misconfiguration
Output Format
None
Mode
None
Debug Output
Operating System
macOS & Linux (Aquatic containers)
Version
Checklist
trivy clean --allBeta Was this translation helpful? Give feedback.
All reactions