EOL for Oracle Linux OS is not aligned with the EOL date mentioned in official site #7479
Closed
s-reddy1498
started this conversation in
Bugs
Replies: 1 comment
-
EOL dates have been updated in #7480 |
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
Description
For Oracle we have provided EOL for version 7 as 23 Aug 2024, but in EOL site it is provided as 31 Dec 2024. This might effect the fix version and remediation info for a CVE.
i.e. This might cause an issue if we have any CVE for which the fix version should be upgrade OS to oracle Linux of version 7, but will be shown as upgrade to oraclelinux:8 version as the version 7 has reached EOL according to date mention in trivy detector.
Desired Behavior
The EOL date should be in-lined.
Actual Behavior
Mismatch in the EOL date, which might cause an issue if we have any CVE in oraclelinux:6 OS for which the fix version should be upgrade OS to oracle Linux of version 7, but will be shown as upgrade to oraclelinux:8 version as the version 7 has reached EOL according to date mention in Trivy detector.
Reproduction Steps
Target
None
Scanner
None
Output Format
None
Mode
None
Debug Output
Operating System
Oracle Linux
Version
Checklist
trivy clean --all
Beta Was this translation helpful? Give feedback.
All reactions