Replies: 2 comments 5 replies
-
@DmitriyLewen is on vacation. @nikpivkin @afdesk Can you please take a look? |
Beta Was this translation helpful? Give feedback.
2 replies
-
This is a bug. I reproduce this only when there are dev dependencies. The structure of some fields has changed in the lock file v6. A fix was released for |
Beta Was this translation helpful? Give feedback.
3 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
Description
Trivy does not find any vulnerabilities or SBOMs in pnpm-lock.yaml files at all
Desired Behavior
Trivy should find at least some vulnerabilities or dependencies
Actual Behavior
Trivy finds none
Reproduction Steps
Target
Filesystem
Scanner
Vulnerability
Output Format
JSON
Mode
Standalone
Debug Output
Checklist
trivy --reset
Beta Was this translation helpful? Give feedback.
All reactions