False alibaba-access-key-id detection in pnpm cache for @types/react.json #5617
Labels
kind/bug
Categorizes issue or PR as related to a bug.
scan/secret
Issues relating to secret scanning
Discussed in #5613
Originally posted by vonazt November 20, 2023
IDs
alibaba-access-key-id
Description
Running trivy v.0.47.0 against built Docker image that includes @types/react v18.2.37 and using pnpm as a package manager returns
HIGH: Alibaba (alibaba-access-key-id)
in/root/.cache/pnpm/metadata/registry.npmjs.org/@types/react.json
. The.json
file appears to include theltai
string in two hashes, which appears to have been a previous bug that was fixed: #3065Reproduction Steps
Target
Container Image
Scanner
Secret
Target OS
No response
Debug Output
Version
Checklist
-f json
that shows data sources and confirmed that the security advisory in data sources was correctThe text was updated successfully, but these errors were encountered: