Skip to content

CVE scans based on apk/db/installed might miss some CVEs #5474

@eriknordmark

Description

@eriknordmark

Describe the unexpected behaviour

Some small linuxkit or lf-edge/eve* containers only deliver a file or two from an Alpine source.
An examples of that is lfedge/eve-grub which does not have an apk/db/installed file but does have a few binaries from a (patched) Linux package.

Metadata

Metadata

Assignees

Labels

No labels
No labels

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions