Netcracker / Netcracker/qubership-testing-platform-itf-executor
[Bug]: Security-Scan job found vulnerabilities in the latest docker image
Nobody has claimed this yet.
- Dominant language
- Java
- Stars
- 0
- Forks
- 2
- Avg merge
- 1d 20h
- Merged PRs (30d)
- 3
Description
Describe the bug
Security-Scan job was added to the repository by DevOps team.
And, the 1st run produced a list of vulnerabilities found in the latest docker image (1.0.3 release).
Vulnerabilities can be viewed at:
- Security tab, then 'Vulnerability alerts' / 'Code scanning' on the left menu.
Also, files are attached to the issue.
Vulnerabilities should be analyzed, then fixed or planned to be fixed or dismissed due to some reason.
To Reproduce
Security-Scan job is executed by the schedule, each Sunday at 03-00 GMT+0.
Also, it can be invoked manually, via:
- Actions / Security scan docker packages,
- then 'Run workflow' button
- In the popup window, leave all fields unchanged to scan the latest tag/release, or enter full docker image link in the 'Docker image' field,
- then click 'Run workflow' button on the bottom of the popup.
Version
No response
Logs
trivy-qubership_testing_platform_itf_executor_transfer_latest.sarif.zip
trivy-qubership_testing_platform_itf_executor_latest.sarif.zip
grype-qubership_testing_platform_itf_executor_transfer_latest.sarif.zip
grype-qubership_testing_platform_itf_executor_latest.sarif.zip
Additional information
No response
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start with the Security tab's Vulnerability alerts and Code scanning results, then review the attached Trivy and Grype SARIF reports for the 1.0.3 image. Run the Actions / Security scan docker packages workflow against the latest tag to confirm findings. Done means each vulnerability is fixed, assigned a remediation plan, or dismissed with a documented reason.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- docker, java
- Domain
- devops, security
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Quiet
- Clarity
- Needs clarification
- Newbie friendliness
- 35/100