4 ms·
We eliminated 1,400 CVEs in NanoClaw's container images
- KaiserPro 2mo agoso s/bookworm/trixie/g didn't work then? Yes, this is mostly a joke, I am able to understand the difference between base distros.
- iririririr 2mo agoa spot on "joke". deb12 is gone for a month now.
- KaiserPro 2mo agoalthough as of today, python-trixie has three CVEs, two of which are perl
- halestock 2mo agoPretty impressive to introduce 1400 CVEs in a project that's only ~7 months old.
- devin 2mo agoIf the thing measuring whether there are CVEs is also the thing creating said CVEs, are we sure they are even CVEs? Deduped? Etc.
- deleted 2mo ago[deleted]
- deleted 2mo ago[deleted]
- GavCo 2mo agoThese are CVEs in the base image and in standard lib dependencies. For example, just scanned an unhardened image I built today: Unhardened: docker.io/nanoco/nanoclaw:agent-alpha 71 packages, 344 unique CVEs, linux/arm64 PACKAGE VERSION TYP C H M L N TOT ----------------------------------------------------------- expat 2.5.0 deb 0 4 18 1 2 25 curl 7.88.1 deb 4 4 6 0 7 21 hono 4.12.14 npm 0 1 18 2 0 21 libtiff 4.5.0 deb 0 2 1 1 15 20 perl 5.36.0 deb 5 6 3 0 3 17 pnpm 10.33.0 npm 0 8 7 0 0 15 glibc 2.36 deb 1 2 2 1 7 13 openjpeg 2.5.0 deb 0 0 3 1 9 13 cups 2.4.2 deb 0 2 8 0 1 11 glib2 2.74.6 deb 1 7 1 0 1 10 tar 1.34(+2) deb 1 1 7 0 1 10 llvm 15.0.6 deb 0 0 0 1 9 10 sqlite3 3.40.1 deb 1 2 3 0 3 9 nss 3.87.1 deb 1 0 3 0 4 8 avahi 0.8 deb 0 0 8 0 0 8 util-linux 2.38.1 deb 0 0 3 0 2 7 elf 0.188 deb 0 0 0 0 7 7 libssh2 1.10.0 deb 1 4 1 0 0 6 openldap 2.5.13 deb 0 1 0 0 5 6 chromium 151.0.7922.108 deb 0 5 0 0 0 5 ----------------------------------------------------------- UNIQUE CVEs 16 68 121 17 119 344 (+51 more packages, 102 findings) C/H/M/L/N = critical/high/medium/low/negligible. Counts are unique CVEs: binaries from one source package are grouped (libcurl4 + libcurl3-gnutls + curl = curl), so a CVE hitting three of them counts once, not three times.
- viccis 2mo agoAre these real findings, or a situation in which fixes have been backported? At one place I worked, the corpsec guys were wildly incompetent and would try to bury me in "CVEs" in my systems that were nothing but "vulnerable" software versions with all of the "identified" vulnerabilities fixed by Debian backported patches.
- deleted 2mo ago[deleted]
- m4rtink 2mo agoSo it has too many dependencies l, which are themselves also CVE magnets ? Maybe they could depend on less items that are more secure ?
- random3 2mo agoIt’s like it’s made of CVEs. First 50-100 should be a good sign if it’s cleaner to start over.
- mohamedkoubaa 2mo agoHold my beer
- iandanforth 2mo agoI don't understand the 'custom patch' strategy over 'fix the app with a major version change' strategy.
- aliasxneo 2mo agoI'm convinced you can tackle 5-10 "CVEs" a day, make a little dashboard, put some pretty graphs on it, and send it to your exec team and probably get accolades. Nevermind that the CVEs had nothing to do with your product.
- nathancahill 2mo agoThis is how Vanta et al. make millions.
- paulryanrogers 2mo agoI don't think Vanta itself even scans for CVEs? They scan for compliance which includes tooling that may look for CVEs, like Dependabot. Scanning companies should be sophisticated enough to distinguish invalid CVEs and back ported fixes.
- lokar 2mo agoMy favorite urgent must fix CVE from compliance was a bug in the Linux PCMCIA driver on some EC2 VMs.
- sriram_sun 2mo agoWhy is that even part of the image?
- lokar 2mo agoIt was a stock/default kernel setup, before my time.
- chrismorgan 2mo agoI don’t say it’s the case there (it probably isn’t, you probably need hardware access or root), but sometimes those sorts of things do actually matter because there’s a way of causing them to be run anyway. This is why it’s good to exclude things you don’t need. The less there is, the fewer places there are for problems to lurk.
- evanjrowley 2mo agoWhy is the Node ecosystem like this? Why do people continue to choose it for popular projects vs. anything else?
- itintheory 2mo agoIt's the opposite of NIH syndrome. Need to left pad a string? Just import a library from some rando on the internet!
- sophacles 2mo agoWhen node was new there were many browsers (different rendering and js engines, not just chrome reskins) and standards and "proto standards" were moving very fast. Different browsers and versions would have very different support for CSS directives, tag behavior, etc. This was a real pain in the ass to make a site consistent across different browsers - every other line of code would require a full switch statement based on browser and version it seemed, and all of these things would need updating every time some browser had an update. The answer to this was something called polyfills, a library that did something as simple as element.center() with just 500 lines of code to make it consistent on all browsers, and all the places you want to center that element are updated by the polyfill authors and your code doesn't need to be touched. All the sites that weren't using good polyfills broke (or at least looked terrible) for days every time there was a new $browser update. Since thats the javascript environment node was born into, the style was carried over by inertia and habit, for better and worse.
- ljm 2mo agoBecause, like it or not, it does Write Once, Use Anywhere better than Java ever did. It is pretty much the lowest common denominator for code.
- eviks 2mo agoPrimarily because of the original sin of JS being an awfully designed language. Partially because it's the most popular.
- tptacek 2mo ago
- tptacek 2mo agoIf you're not a security person, the unspoken subtext here: the overwhelming majority of these "CVEs" do not matter to the project, and a very large number of them don't matter at all. They're pro-forma findings, like ReDOS in code paths that are rarely used, or, even more commonly, "prototype pollution" issues.
- doc_ick 2mo agoSo they do matter, just unlikely to be executed.
- Surac 2mo agolet me guess. they wrote a promt that told claude do undo all bugs?
- bryan0 2mo agoWhy hasn't looking at EPSS (Exploit Prediction Scoring System) become a more standard approach than just raw CVEs?
- prymitive 2mo agoFor those unfamiliar, “CVE” stands for “CV Enrichment”, common slang in Posture Engineering
- bedros 2mo agoCommon Vulnerabilities and Exposures https://en.wikipedia.org/wiki/Common_Vulnerabilities_and_Exposures https://en.wikipedia.org/wiki/Common_Vulnerabilities_and_Exp...
- EdwardDiego 2mo agoI feel you missed the joke.
- evanjrowley 2mo agoDiscovered a new legit CVE today during a meeting with some other engineers. I’m going to make sure the one who originally brought it up gets to put it on his résumé. The world needs more people like that.
- raver1975 2mo agoThat's what happens when you vibe code.
- 482937632992 2mo ago[dead]
- deleted 2mo ago[deleted]
- sajithdilshan 2mo agoI wonder how many new CVEs were introduced while patching these
- eviks 2mo agoWhat is NanoClaw? Glad you asked: > NanoClaw is a secure, lightweight alternative to OpenClaw.
- overgard 2mo agoI'm pretty skeptical you can call any claw-like thing secure unless you solve prompt injection.
- stavros 2mo agoSecurity isn't binary. There's nothing that's "secure" unless you define a threat model first.
- Hamuko 2mo agoIf the lightweight alternative has 1400 CVEs, how many does OpenClaw have?
- cdnsteve 2mo agoWhat do you use for Nanoclaw's sandboxing?
- pokstad 2mo agoI was intrigued by nano claws more “secure” marketing, but I couldn’t believe how loose and vibe coded the installation and set up process was. My god it’s full of prompts.