3 ms·
Last closed issue was march, many initial issues mentioning security vulnerabilities since April that have not been responded to..
by briffle 2y ago
Last closed issue was march, many initial issues mentioning security vulnerabilities since April that have not been responded to..
- pella 2y agoimho: A false positive CVE list is an issue elsewhere as well, and it's important to understand that there's not much a Docker Postgres maintainer can do if the problem lies in the Debian or Ubuntu package and isn't getting fixed for some reason. https://github.com/docker-library/faq#why-does-my-security-scanner-show-that-an-image-has-cves https://github.com/docker-library/faq#why-does-my-security-s... It's also advisable not to use the default settings: https://pythonspeed.com/articles/docker-security-scanner/ https://pythonspeed.com/articles/docker-security-scanner/ "trivy --ignore-unfixed <image>" Of course, it is advisable for the image maintainer to rebuild the Docker image weekly or bi-weekly to ensure all recent patches are included. However, for those who prioritize security, it is best to build the image themselves to guarantee up-to-date packages.
- blueflow 2y ago> e.g., CVE-2005-2541 is considered a High severity vulnerability, but in Debian is considered “intended behavior,” making it a feature, not a bug. CVE-2005-2541 is documented & required behavior for the tar archive: https://marc.info/?l=bugtraq&m=112360016019030&w=2 https://marc.info/?l=bugtraq&m=112360016019030&w=2 . Infuriating that the CVE was seen as valid enough to get a number.