3 ms·
Pretty impressive to introduce 1400 CVEs in a project that's only ~7 months old.
by halestock 2mo ago
Pretty impressive to introduce 1400 CVEs in a project that's only ~7 months old.
- devin 2mo agoIf the thing measuring whether there are CVEs is also the thing creating said CVEs, are we sure they are even CVEs? Deduped? Etc.
- deleted 2mo ago[deleted]
- deleted 2mo ago[deleted]
- GavCo 2mo agoThese are CVEs in the base image and in standard lib dependencies. For example, just scanned an unhardened image I built today: Unhardened: docker.io/nanoco/nanoclaw:agent-alpha 71 packages, 344 unique CVEs, linux/arm64 PACKAGE VERSION TYP C H M L N TOT ----------------------------------------------------------- expat 2.5.0 deb 0 4 18 1 2 25 curl 7.88.1 deb 4 4 6 0 7 21 hono 4.12.14 npm 0 1 18 2 0 21 libtiff 4.5.0 deb 0 2 1 1 15 20 perl 5.36.0 deb 5 6 3 0 3 17 pnpm 10.33.0 npm 0 8 7 0 0 15 glibc 2.36 deb 1 2 2 1 7 13 openjpeg 2.5.0 deb 0 0 3 1 9 13 cups 2.4.2 deb 0 2 8 0 1 11 glib2 2.74.6 deb 1 7 1 0 1 10 tar 1.34(+2) deb 1 1 7 0 1 10 llvm 15.0.6 deb 0 0 0 1 9 10 sqlite3 3.40.1 deb 1 2 3 0 3 9 nss 3.87.1 deb 1 0 3 0 4 8 avahi 0.8 deb 0 0 8 0 0 8 util-linux 2.38.1 deb 0 0 3 0 2 7 elf 0.188 deb 0 0 0 0 7 7 libssh2 1.10.0 deb 1 4 1 0 0 6 openldap 2.5.13 deb 0 1 0 0 5 6 chromium 151.0.7922.108 deb 0 5 0 0 0 5 ----------------------------------------------------------- UNIQUE CVEs 16 68 121 17 119 344 (+51 more packages, 102 findings) C/H/M/L/N = critical/high/medium/low/negligible. Counts are unique CVEs: binaries from one source package are grouped (libcurl4 + libcurl3-gnutls + curl = curl), so a CVE hitting three of them counts once, not three times.
- viccis 2mo agoAre these real findings, or a situation in which fixes have been backported? At one place I worked, the corpsec guys were wildly incompetent and would try to bury me in "CVEs" in my systems that were nothing but "vulnerable" software versions with all of the "identified" vulnerabilities fixed by Debian backported patches.
- deleted 2mo ago[deleted]
- m4rtink 2mo agoSo it has too many dependencies l, which are themselves also CVE magnets ? Maybe they could depend on less items that are more secure ?
- random3 2mo agoIt’s like it’s made of CVEs. First 50-100 should be a good sign if it’s cleaner to start over.
- mohamedkoubaa 2mo agoHold my beer