Skip to content

Add vuln-type parameter to CS Trivy SBOM scan

Yasha Rise requested to merge add-vuln-type-param-to-cs-trivy-sbom-scan into master

What does this MR do?

Pass the vuln-type parameter, based on the "report language-specific findings" option to the Trivy SBOM command in container scanning, to avoid scanning non-OS packages unnecessarily. Resolves Non OS packages are present in the CycloneDX SB... (gitlab-org/gitlab#435390 - closed) • Yasha Rise • 17.1.

What are the relevant issue numbers?

gitlab-org/gitlab#435390 (closed)

Does this MR meet the acceptance criteria?

Edited by Oscar Tovar

Merge request reports