Repository navigation
Trivy flags 9 Go CVEs in the sf binary — is this expected? #295
|
Hello, We scan our Docker image with Trivy and it reports 9 HIGH vulnerabilities attributed to /usr/local/bin/sf (where we store the binary).
Advisories (Avd.aquasec.com): CVE-2026-46603, CVE-2026-33818, CVE-2026-39821, CVE-2026-46600, CVE-2026-56853, CVE-2026-56858, CVE-2026-56859, CVE-2026-56860, CVE-2026-56862. We thought the new version would fix those but they don't. For context: sf runs as a short-lived CLI in our pipeline (reads local files, no network listeners), so the practical exposure of these CVEs looks low — we mainly need to know whether we can safely document this as accepted risk or should wait for a patched release. Thanks ! |
Replies: 1 comment 3 replies
|
Hi @abarbosa-ssg thanks for raising this discussion. No problem for me to do another point release tonight with an update mod file to address these. |
Hi @abarbosa-ssg thanks for raising this discussion. No problem for me to do another point release tonight with an update mod file to address these.
I don't run Trivy myself & typically will only be aware of CVEs when I get Github dependabot alerts. Happy in future to receive issues/discussions to bring my attention to any further CVEs you encounter