Netcracker / Netcracker/qubership-testing-platform-itf-executor

[Bug]: Security-Scan job found vulnerabilities in the latest docker image

Open
#54 2 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

bug
Dominant language
Java
Stars
0
Forks
2
Avg merge
1d 20h
Merged PRs (30d)
3

Description

Describe the bug

Security-Scan job was added to the repository by DevOps team.
And, the 1st run produced a list of vulnerabilities found in the latest docker image (1.0.3 release).
Vulnerabilities can be viewed at:

  • Security tab, then 'Vulnerability alerts' / 'Code scanning' on the left menu.

Also, files are attached to the issue.

Vulnerabilities should be analyzed, then fixed or planned to be fixed or dismissed due to some reason.

To Reproduce

Security-Scan job is executed by the schedule, each Sunday at 03-00 GMT+0.
Also, it can be invoked manually, via:

  • Actions / Security scan docker packages,
  • then 'Run workflow' button
  • In the popup window, leave all fields unchanged to scan the latest tag/release, or enter full docker image link in the 'Docker image' field,
  • then click 'Run workflow' button on the bottom of the popup.
Version

No response

Logs

trivy-qubership_testing_platform_itf_executor_transfer_latest.sarif.zip
trivy-qubership_testing_platform_itf_executor_latest.sarif.zip
grype-qubership_testing_platform_itf_executor_transfer_latest.sarif.zip
grype-qubership_testing_platform_itf_executor_latest.sarif.zip

Additional information

No response

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start with the Security tab's Vulnerability alerts and Code scanning results, then review the attached Trivy and Grype SARIF reports for the 1.0.3 image. Run the Actions / Security scan docker packages workflow against the latest tag to confirm findings. Done means each vulnerability is fixed, assigned a remediation plan, or dismissed with a documented reason.

Written by the indexing model from the issue text.

Assessment

Tech stack
docker, java
Domain
devops, security
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Quiet
Clarity
Needs clarification
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.