<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Alpine&#x2F;APK-based container images show no vulnerabilities despite CVEs existing in PGVD]]></title><description><![CDATA[<p dir="auto">We are evaluating ProGet for container image vulnerability scanning and comparing results with Trivy. We have identified an inconsistency in vulnerability detection specifically for Alpine Linux-based container images.</p>
<p dir="auto">Problem: ProGet does not surface OS-level vulnerabilities for Alpine (APK) based container images, while Ubuntu/Debian (dpkg) based images are scanned correctly and vulnerabilities are detected as expected.</p>
<p dir="auto">Example: Image: hysnsec/nginx-advanced (Alpine 3.10.2)</p>
<p dir="auto">Trivy detects multiple CVEs including CVE-2021-36159 (CRITICAL) in apk-tools 2.10.4-r2, CVE-2021-30139 (HIGH) in apk-tools, CVE-2021-28831 in busybox 1.30.1-r2, and CVE-2020-1967 in libcrypto1.1.<br />
ProGet correctly extracts and displays the APK package inventory (package names, versions, and architecture are all visible in the Packages tab).<br />
However, ProGet reports "None" for vulnerabilities on all Alpine packages.<br />
Verified in PGVD: We confirmed that the relevant CVEs exist in the Inedo vulnerability database:</p>
<p dir="auto">PGV-2156903 (CVE-2021-36159)<br />
PGV-2156988 (CVE-2021-36159)<br />
Despite the CVEs being present in PGVD, they are not matched against the detected APK packages.</p>
<p dir="auto">What we have checked:</p>
<p dir="auto">Vulnerability Database Updater job runs successfully and on schedule<br />
Layer Scanning is enabled on the Docker feed<br />
Package inventory is detected correctly (APK packages with versions are visible)<br />
Ubuntu/Debian-based images DO return vulnerabilities correctly — confirming that container scanning, license, and PGVD are working<br />
The issue is consistent across multiple Alpine-based images and multiple scans<br />
The Compliance Analyzer scheduled job shows an error status (red icon)<br />
Our assessment: It appears that PGVD has the CVE entries but lacks the affected-package mappings for Alpine APK packages. The CVE-to-package correlation works for dpkg (Debian/Ubuntu) but not for APK (Alpine). We suspect the Alpine Security Database (<a href="http://security.alpinelinux.org" rel="nofollow">security.alpinelinux.org</a>) may not be integrated as a data source for PGVD's package-level mappings.</p>
<p dir="auto">Environment:</p>
<p dir="auto">ProGet 2025.26 (Build 11), Trial Edition<br />
Running on Docker (Linux VM)<br />
Nginx reverse proxy in front of ProGet<br />
PostgreSQL built-in database<br />
Request: Could you confirm whether Alpine/APK vulnerability matching is currently supported in PGVD? If not, is there a timeline for adding Alpine Security Database as a data source? Are there any workarounds we can use in the meantime?<br />
<img src="/assets/uploads/files/1776680864954-image-3.png" alt="Image (3).png" class="img-responsive img-markdown" /> <img src="/assets/uploads/files/1776680864957-image-2.png" alt="image (2).png" class="img-responsive img-markdown" /> <img src="/assets/uploads/files/1776680864963-image-1.png" alt="image (1).png" class="img-responsive img-markdown" /></p>
]]></description><link>https://forums.inedo.com/topic/5727/alpine-apk-based-container-images-show-no-vulnerabilities-despite-cves-existing-in-pgvd</link><generator>RSS for Node</generator><lastBuildDate>Tue, 28 Apr 2026 13:13:38 GMT</lastBuildDate><atom:link href="https://forums.inedo.com/topic/5727.rss" rel="self" type="application/rss+xml"/><pubDate>Mon, 20 Apr 2026 10:27:52 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Alpine&#x2F;APK-based container images show no vulnerabilities despite CVEs existing in PGVD on Mon, 20 Apr 2026 10:27:52 GMT]]></title><description><![CDATA[<p dir="auto">We are evaluating ProGet for container image vulnerability scanning and comparing results with Trivy. We have identified an inconsistency in vulnerability detection specifically for Alpine Linux-based container images.</p>
<p dir="auto">Problem: ProGet does not surface OS-level vulnerabilities for Alpine (APK) based container images, while Ubuntu/Debian (dpkg) based images are scanned correctly and vulnerabilities are detected as expected.</p>
<p dir="auto">Example: Image: hysnsec/nginx-advanced (Alpine 3.10.2)</p>
<p dir="auto">Trivy detects multiple CVEs including CVE-2021-36159 (CRITICAL) in apk-tools 2.10.4-r2, CVE-2021-30139 (HIGH) in apk-tools, CVE-2021-28831 in busybox 1.30.1-r2, and CVE-2020-1967 in libcrypto1.1.<br />
ProGet correctly extracts and displays the APK package inventory (package names, versions, and architecture are all visible in the Packages tab).<br />
However, ProGet reports "None" for vulnerabilities on all Alpine packages.<br />
Verified in PGVD: We confirmed that the relevant CVEs exist in the Inedo vulnerability database:</p>
<p dir="auto">PGV-2156903 (CVE-2021-36159)<br />
PGV-2156988 (CVE-2021-36159)<br />
Despite the CVEs being present in PGVD, they are not matched against the detected APK packages.</p>
<p dir="auto">What we have checked:</p>
<p dir="auto">Vulnerability Database Updater job runs successfully and on schedule<br />
Layer Scanning is enabled on the Docker feed<br />
Package inventory is detected correctly (APK packages with versions are visible)<br />
Ubuntu/Debian-based images DO return vulnerabilities correctly — confirming that container scanning, license, and PGVD are working<br />
The issue is consistent across multiple Alpine-based images and multiple scans<br />
The Compliance Analyzer scheduled job shows an error status (red icon)<br />
Our assessment: It appears that PGVD has the CVE entries but lacks the affected-package mappings for Alpine APK packages. The CVE-to-package correlation works for dpkg (Debian/Ubuntu) but not for APK (Alpine). We suspect the Alpine Security Database (<a href="http://security.alpinelinux.org" rel="nofollow">security.alpinelinux.org</a>) may not be integrated as a data source for PGVD's package-level mappings.</p>
<p dir="auto">Environment:</p>
<p dir="auto">ProGet 2025.26 (Build 11), Trial Edition<br />
Running on Docker (Linux VM)<br />
Nginx reverse proxy in front of ProGet<br />
PostgreSQL built-in database<br />
Request: Could you confirm whether Alpine/APK vulnerability matching is currently supported in PGVD? If not, is there a timeline for adding Alpine Security Database as a data source? Are there any workarounds we can use in the meantime?<br />
<img src="/assets/uploads/files/1776680864954-image-3.png" alt="Image (3).png" class="img-responsive img-markdown" /> <img src="/assets/uploads/files/1776680864957-image-2.png" alt="image (2).png" class="img-responsive img-markdown" /> <img src="/assets/uploads/files/1776680864963-image-1.png" alt="image (1).png" class="img-responsive img-markdown" /></p>
]]></description><link>https://forums.inedo.com/post/19568</link><guid isPermaLink="true">https://forums.inedo.com/post/19568</guid><dc:creator><![CDATA[kien.buit_2449]]></dc:creator><pubDate>Mon, 20 Apr 2026 10:27:52 GMT</pubDate></item><item><title><![CDATA[Reply to Alpine&#x2F;APK-based container images show no vulnerabilities despite CVEs existing in PGVD on Mon, 20 Apr 2026 13:09:23 GMT]]></title><description><![CDATA[<p dir="auto">Hi <a class="plugin-mentions-user plugin-mentions-a" href="https://forums.inedo.com/uid/3902">@kien-buit_2449</a> ,</p>
<p dir="auto">Thanks for sharing the details. I was able to confirm this is some kind of bug (data problem?) in ProGet. It appears to be in the datafile that's downloaded/imported into ProGet, though I'm not sure.</p>
<p dir="auto">Stay tuned, and we'll let you know once a fix is ready.</p>
<p dir="auto">Thanks,<br />
Alana</p>
]]></description><link>https://forums.inedo.com/post/19569</link><guid isPermaLink="true">https://forums.inedo.com/post/19569</guid><dc:creator><![CDATA[atripp]]></dc:creator><pubDate>Mon, 20 Apr 2026 13:09:23 GMT</pubDate></item><item><title><![CDATA[Reply to Alpine&#x2F;APK-based container images show no vulnerabilities despite CVEs existing in PGVD on Tue, 21 Apr 2026 21:12:17 GMT]]></title><description><![CDATA[<p dir="auto">Hi <a class="plugin-mentions-user plugin-mentions-a" href="https://forums.inedo.com/uid/3902">@kien-buit_2449</a>,</p>
<p dir="auto">This is partially fixed in our vulnerability aggregator.  You should see alpine vulnerabilities showing up next time your vulnerability updated runs.  I also recreated a situation where certain packages may not be removed upon update of the vulnerability.  I have created ticket <a href="https://issues.inedo.com/issue/PG-3263" class="inedo-link inedo-link-pg" rel="nofollow">PG-3263</a> to fix that issue.  That fix will be released next week in ProGet 2025.27.</p>
<p dir="auto">Thanks,<br />
Rich</p>
]]></description><link>https://forums.inedo.com/post/19586</link><guid isPermaLink="true">https://forums.inedo.com/post/19586</guid><dc:creator><![CDATA[rhessinger]]></dc:creator><pubDate>Tue, 21 Apr 2026 21:12:17 GMT</pubDate></item></channel></rss>