Trivy Overloaded When Multiple Projects Are Uploaded Without Delay #4453
Labels
defect
Something isn't working
integration/trivy
Related to the Trivy integration
p2
Non-critical bugs, and features that help organizations to identify and reduce risk
size/M
Medium effort
Current Behavior
When uploading 200 projects sequentially via the API without introducing any delay, the analyzers successfully assign vulnerabilities to the components, Trivy takes significantly longer—sometimes exceeding 10 minutes per project.
Adding a reasonable delay between uploads (e.g., 50 seconds in my case) allows Trivy to react and function properly.
Steps to Reproduce
Expected Behavior
Trivy should handle sequential project uploads with processing times comparable to other analyzers.
Actual Behavior
Trivy takes significantly longer to process projects than other analyzers when handling sequential uploads without delay. This creates a bottleneck in vulnerability assignment and slows down the overall process.
Dependency-Track Version
4.12.2
Dependency-Track Distribution
Executable WAR
Database Server
PostgreSQL
Database Server Version
No response
Browser
Mozilla Firefox
Checklist
The text was updated successfully, but these errors were encountered: