Replies: 1 comment 2 replies
-
Hey @BenHirschbergCa I understand the confusion. Quay.io is running Clair v2 - which is the older version of Clair. Clair V4 overhauled a lot matching code and database sources. We typically see Clair V4 matching more accurately. It's incorrect to compare quay.io scan results with Clair V4. We are in the process of fork lifting Clair V4 into quay.io so in time, these results will be at parity. |
Beta Was this translation helpful? Give feedback.
2 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
I have been happily scanning my images "on prem" for a time using latest and greatest clair, when someone showed me that the results of the same images scanned by quay.io (registry built in feature) and my clair are very different.
I was told, that quay.io uses clair, but it looks like it returns more vulnerabilities (in my specific case 4x) than my local vanilla clair installation.
I was wondering if I am doing something wrong. Should I be updating my local vulnerability DB or etc.
Thx
B
Beta Was this translation helpful? Give feedback.
All reactions