This message was deleted.
# neuvector_suse-security
a
This message was deleted.
q
Arguments among CVE scanners is common, sadly. And before I even got to that point in your post, my brain went "_Is it RedHat? I'll bet it's RedHat_" 😄 A quick (🤞 ) and dirty solution may be to "accept" the CVEs in the UI. Guessing it's not 10k CVEs, but 10k hits across your org, correct?
a
This was just a scan done on a single node, patched w/ dnf update last week! We were looking for a way to sort or filter by the "Informational" findings so we could quickly accept/eliminate those, but didn't see an option for that.
And it was 23000 findings 🫠
🤯 1
q
That's indeed a LOT. Are there a ton of packages on there?
In your opinion would filtering against the Errata help, if you could do that?
a
There aren't honestly that many packages installed, its a fairly minimal build for k8s prep
I do think filtering against errata could help - it seems that I'm not the first person to run into false positives w/ RedHat back-porting fixes to earlier versions
q
Short version: There's a bit of a ground-up rewrite of scanning coming in 2026; issues like this are top of mind.