False detection of spark-core_2.12:3.4.2 as spark-core_2.12:3.0.1 #7836
Closed
Tsuesun
started this conversation in
False Detection
Replies: 1 comment
-
Hello @Tsuesun This problem related with I created #7844 for this case. Regards, Dmitriy |
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
IDs
CVE-2023-22946
Description
Trivy seems to detect the wrong version of spark-core as a much earlier version than the one that is defined in the pom leading to a false positive detection
Reproduction Steps
run trivy filesystem pom.xml
...
Version
Checklist
-f json
that shows data sources and confirmed that the security advisory in data sources was correctBeta Was this translation helpful? Give feedback.
All reactions