Skip to content

conflicting security reports with other SCA tools #196

@aep-sunlife

Description

@aep-sunlife

Docker Scout often presents more, or fewer CVE's compared with other SCA tools. For example, Docker Scout and Snyk Container tend to disagree on which CVE's apply to various images. Sometimes Docker Scout shows more CVE's. Sometimes Snyk Container shows more CVE's.

Can we please improve the CVE data for Docker Scout so that it behaves as a superset of the Snyk Database?

https://snyk.io/

https://security.snyk.io/

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions