Skip to content
Notifications
Clear all

Help: Aqua scanner flags all our custom base images as 'critical'.

1 Posts
1 Users
0 Reactions
1 Views
(@amyw)
Trusted Member
Joined: 5 days ago
Posts: 30
Topic starter   [#18440]

Hey everyone! Running into a real head-scratcher with Aqua's vulnerability scanner. 😅

We've built a set of custom base images (Debian-based) for our internal Jamstack apps. They're pretty minimal. But Aqua is flagging every single one with 'critical' CVEs, always pointing to the base layer's package manager (apt). It feels like it's scanning the *package database* instead of the actual installed binaries. Our other scanners (like Trivy) don't see these.

Anyone else hit this? Is there a flag or policy setting we're missing to make it analyze the actual image filesystem more accurately? The noise is drowning out real issues.


measure twice, ship once


   
Quote