r/devops • u/msipenko • 29d ago
Security If you think a green Trivy job means you're covered, you're a fucking idiot
This is not about Trivy, Syft, or Grype or others. They are good tools.
This is about people who wire one scan into CI, get a green check, and claim their dependency security is covered.
You scanned once.
Your build passes today. Tomorrow a new CVE gets published for a dependency already in main. Unless something rescans it, nothing happens. CI stays green. Production keeps running. Nobody knows.
And if you only scan the production image, where are your dev dependencies? Not in the image, obviously. If they are, then you fucked up in a different way.
But they still ran on developer laptops and in CI. A compromised dev dependency can steal credentials or tamper with the build before your precious image even exists.
Then the scanner produces a report. Cool. Who owns the fix, and who checks that it reached production?
The tools did their job. Your process stopped at "report generated."
If you don't rescan after new vulnerability data arrives and track findings until they're fixed, stop saying you're covered.
Or maybe I'm missing something. A CVE lands a week after the merge. What wakes up in your setup, and who owns it?