Skip to content

Conversation

@gdsmith
Copy link

@gdsmith gdsmith commented Jan 12, 2026

Updates

  • Affected products

Comments
Seems MS has released a 12.2.1 version that is causing false positives

@github-actions github-actions bot changed the base branch from main to gdsmith/advisory-improvement-6638 January 12, 2026 14:43
@shelbyc
Copy link
Contributor

shelbyc commented Jan 16, 2026

Hi @gdsmith, I read aquasecurity/trivy#9745 to get an idea of what's going on, but BLUF: I can't change the patched version to 12.2.1 because there is no version 12.2.1 of https://mvnrepository.com/artifact/com.microsoft.sqlserver/mssql-jdbc/versions, only 12.2.1.jre8 and 12.2.1.jre11.

For more detail:

I'm not sure why people in aquasecurity/trivy#9745 are having issues with 12.2.1 being incorrectly marked as vulnerable, but if I had to guess, it may have something to do with 12.2.1 with no suffix not existing in Maven.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants