Skip to content

Custom vuln feeds support #5642

@plakun

Description

@plakun

Current Behavior

Good afternoon. We use the ALT Linux distribution, which is not officially supported by Trivy. The distribution vendor independently enriches the Trivy databases with information about its packages and publishes them in its own Docker registry. When using these databases, we obtain a complete vulnerability report for images based on ALT Linux. I deployed a Trivy server that uses the customized vulnerability databases and configured it in the Dependency-Track analyzer settings, but no vulnerabilities are found when analyzing an SBOM.

Custom trivy-DB - docker pull registry.altlinux.org/alt/trivy-db:latest

report.html

Proposed Behavior

When custom databases are specified, Dependency-Track detects all vulnerabilities in the ALT Linux image.

Checklist

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or request

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions