Skip to content
GitLab
  • Menu
Projects Groups Snippets
  • Help
    • Help
    • Support
    • Community forum
    • Submit feedback
  • Sign in
  • H Harbor
  • Project information
    • Project information
    • Activity
    • Labels
    • Members
  • Repository
    • Repository
    • Files
    • Commits
    • Branches
    • Tags
    • Contributors
    • Graph
    • Compare
    • Locked Files
  • Issues 0
    • Issues 0
    • List
    • Boards
    • Service Desk
    • Milestones
    • Requirements
  • Merge requests 0
    • Merge requests 0
  • CI/CD
    • CI/CD
    • Pipelines
    • Jobs
    • Schedules
    • Test Cases
  • Deployments
    • Deployments
    • Environments
    • Releases
  • Packages & Registries
    • Packages & Registries
    • Package Registry
    • Infrastructure Registry
  • Monitor
    • Monitor
    • Incidents
  • Analytics
    • Analytics
    • Value stream
    • CI/CD
    • Code review
    • Insights
    • Issue
    • Repository
  • Wiki
    • Wiki
  • Snippets
    • Snippets
  • Activity
  • Graph
  • Create a new issue
  • Jobs
  • Commits
  • Issue Boards
Collapse sidebar
  • 小 白蛋
  • Harbor
  • Repository
Switch branch/tag
  • harbor
  • Makefile
Find file BlameHistoryPermalink
  • Daniel Pacak's avatar
    fix(trivy): Bump up Trivy adapter to v0.11.0 · dfcee80a
    Daniel Pacak authored Jun 05, 2020
    This commit bumps up Trivy to resolve the following issues reported
    in the aquasecurity/harbor-scanner-trivy repository:
    
    - https://github.com/aquasecurity/harbor-scanner-trivy/issues/114
    - https://github.com/aquasecurity/harbor-scanner-trivy/issues/108
    
    
    
    Note that this adapter vendors in Trivy v0.9.0 which has changed
    the algorithm for qualifying severities. Previous versions of Trivy
    preferred NVD scores, whereas this version will use vendor score
    whenever it's possible.
    
    We believe it's more suitable approach for qualifying severities.
    Even though this change might impact vulnerability summaries in
    some cases, the total number of vulnerabilities should stay the
    same.
    Signed-off-by: default avatarDaniel Pacak <pacak.daniel@gmail.com>
    dfcee80a

免费DevSecOps平台,让您的项目体验完整的DevSecOps流程,让项目更安全