Skip to content

missing CVE data #206

@mcandre

Description

@mcandre

Docker Scout treats images vulnerable to CVE-2025-11579 as having a clean bill of health with no CVE's.

Whereas Snyk Container identifies this, and other CVE's in the Snyk Vulnerability Database.

https://www.cve.org/CVERecord?id=CVE-2025-11579

https://security.snyk.io/vuln/SNYK-GOLANG-GITHUBCOMNWAPLESRARDECODEV2-13537508

Can we please sync more data between the Docker Scout and Snyk databases? As a developer, it's confusing to see mutually exclusive security reports. Very, very, very often, Docker Scout and Snyk report completely different sets of CVE's.

Metadata

Metadata

Assignees

Labels

No labels
No labels

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions