Skip to content

Vulnerability scans of splunk-library-javalogging 1.11.8 produce no findings where Maven has high CVEs #8352

Answered by DmitriyLewen
AustinIvey asked this question in Q&A
Discussion options

You must be logged in to vote

Hello @AustinIvey
Thanks for your report!

Package ch.qos.logback:logback-core contains these vulnerabilities.
But this package uses provided scope - https://github.com/splunk/splunk-library-javalogging/blob/70f80fa60d2098e81f5f819059964d9304b5f1d5/pom.xml#L207-L212

Trivy doesn't include dependencies with provided scope because these dependencies are not used at runtime - https://trivy.dev/latest/docs/coverage/language/java/#supported-scopes

Regards, Dmitriy

Replies: 1 comment

Comment options

You must be logged in to vote
0 replies
Answer selected by AustinIvey
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
triage/support Indicates an issue that is a support question. scan/vulnerability Issues relating to vulnerability scanning
2 participants