mirror of
https://github.com/aquasecurity/trivy.git
synced 2025-12-21 14:50:53 -08:00
2.3 KiB
2.3 KiB
Language-specific Packages
Trivy automatically detects the following files in the container and scans vulnerabilities in the application dependencies.
| Language | File | Image1 | Filesystem2 | Repository3 | Dev dependencies |
|---|---|---|---|---|---|
| Ruby | Gemfile.lock | ✅ | ✅ | ✅ | included |
| Python | Pipfile.lock | - | ✅ | ✅ | excluded |
| poetry.lock | - | ✅ | ✅ | included | |
| requirements.txt | - | ✅ | ✅ | included | |
| egg package4 | ✅ | ✅ | - | excluded | |
| wheel package5 | ✅ | ✅ | - | excluded | |
| PHP | composer.lock | ✅ | ✅ | ✅ | excluded |
| Node.js | package-lock.json | ✅ | ✅ | ✅ | excluded |
| yarn.lock | ✅ | ✅ | ✅ | ncluded | |
| .NET | packages.lock.json | ✅ | ✅ | ✅ | included |
| Java | JAR/WAR/EAR6 7 | ✅ | ✅ | ✅ | included |
| Go | Binaries built by Go8 | ✅ | ✅ | - | excluded |
| go.sum | - | ✅ | ✅ | included |
The path of these files does not matter.
Example: Dockerfile
-
✅ means "enabled" and
-means "disabled" in the image scanning ↩︎ -
✅ means "enabled" and
-means "disabled" in the filesystem scanning ↩︎ -
✅ means "enabled" and
-means "disabled" in the git repository scanning ↩︎ -
*.egg-info,*.egg-info/PKG-INFO,*.eggandEGG-INFO/PKG-INFO↩︎ -
.dist-info/META-DATA↩︎ -
*.jar,*.war, and*.ear↩︎ -
It requires the Internet access ↩︎
-
UPX-compressed binaries don't work ↩︎