为何Trivy以root与Jenkins用户扫描输出结果不一致?
Trivy扫描结果随执行用户不同出现差异
分别以root用户和Jenkins用户执行Trivy文件系统扫描命令,得到的漏洞结果不一致:
- root用户扫描结果:7个漏洞(MEDIUM:5、HIGH:2)
- Jenkins用户扫描结果:4个漏洞(MEDIUM:4)
已检查文件权限及Trivy配置,未发现异常。
执行命令及输出
root@yyy:~/var/lib/jenkins/jobs/xxx/branches/development/workspace# trivy fs /var/lib/jenkins/jobs/xxx/branches/development/workspace 2024-03-12T17:43:43.527+0300 INFO Vulnerability scanning is enabled 2024-03-12T17:43:43.527+0300 INFO Secret scanning is enabled 2024-03-12T17:43:43.527+0300 INFO If your scanning is slow, please try '--scanners vuln' to disable secret scanning 2024-03-12T17:43:43.527+0300 INFO Please see also https://aquasecurity.github.io/trivy/v0.42/docs/secret/scanning/#recommendation for faster secret detection 2024-03-12T17:43:44.634+0300 INFO Number of language-specific files: 1 2024-03-12T17:43:44.634+0300 INFO Detecting pom vulnerabilities... pom.xml (pom) Total: 7 (UNKNOWN: 0, LOW: 0, MEDIUM: 5, HIGH: 2, CRITICAL: 0) .... jenkins@yyy:~/var/lib/jenkins/jobs/xxx/branches/development/workspace# trivy fs /var/lib/jenkins/jobs/xxx/branches/development/workspace 2024-03-12T17:43:53.616+0300 INFO Vulnerability scanning is enabled 2024-03-12T17:43:53.616+0300 INFO Secret scanning is enabled 2024-03-12T17:43:53.616+0300 INFO If your scanning is slow, please try '--scanners vuln' to disable secret scanning 2024-03-12T17:43:53.616+0300 INFO Please see also https://aquasecurity.github.io/trivy/v0.42/docs/secret/scanning/#recommendation for faster secret detection 2024-03-12T17:43:54.112+0300 INFO Number of language-specific files: 1 2024-03-12T17:43:54.112+0300 INFO Detecting pom vulnerabilities... pom.xml (pom) Total: 4 (UNKNOWN: 0, LOW: 0, MEDIUM: 4, HIGH: 0, CRITICAL: 0) ...
Trivy版本信息
Version: 0.42.1 Vulnerability DB: Version: 2 UpdatedAt: 2024-03-12 12:11:09.459246831 +0000 UTC NextUpdate: 2024-03-12 18:11:09.459246471 +0000 UTC DownloadedAt: 2024-03-12 14:41:57.090100001 +0000 UTC
内容的提问来源于stack exchange,提问作者Mustafa DOGRU
相关产品推荐
相关产品推荐

