Echo¶
Trivy supports these scanners for OS packages.
| Scanner | Supported |
|---|---|
| SBOM | ✓ |
| Vulnerability | ✓ |
| License | ✓ |
The table below outlines the features offered by Trivy.
| Feature | Supported |
|---|---|
| Unfixed vulnerabilities | ✓ |
| Dependency graph | ✓ |
| End of life awareness | - |
SBOM¶
Same as Debian.
Vulnerability¶
Echo offers its own security advisories, and these are utilized when scanning Echo for vulnerabilities.
Data Source¶
See here.
License¶
Same as Debian.
Language Packages¶
Echo provides patched versions of language packages. Trivy identifies them by the version suffix and uses Echo's own security advisories from the Echo OSV feed for them instead of the upstream ones.
| Ecosystem | Version Suffix | Example |
|---|---|---|
| Python | +echo.N |
requests 2.14.2+echo.1 |
Other packages, including those from other ecosystems, are scanned against the upstream advisories as usual.
Note
These packages are detected regardless of the OS, including filesystem and repository scans.