Vulnerability reference ΒΆ

Known limitations and alternatives ΒΆ

Due to Trivy, you'll receive a simplified dependency graph, as Trivy doesn't support Gradle or Maven's dependency resolution.

Dependency-track integrates with Trivy at runtime, ensuring that vulnerabilities from the Docker container are still detected.

Trivy directly parses the .jar files without access to full dependency resolution details.

Gradle and Maven plugins provide a deeper graph of nested transitive dependencies.

Gradle Plugin ΒΆ

??? Gradle Plugin

Plaintext

Maven Plugin ΒΆ

??? Maven Plugin

Plaintext