apache / apache/incubator-seata
使用最新镜像【seataio/seata-server:latest】被检测出大量安全漏洞,要怎么处理呢?
- Dominant language
- Java
- Stars
- 26k
- Forks
- 8.8k
- Avg merge
- 1d 8h
- Merged PRs (30d)
- 4
Description
- [ ] I have searched the [issues](https://github.com/seata/seata/issues) of this repository and believe that this is not a duplicate.
### Ⅰ. Issue Description
使用Docker Hub上的seataio/seata-server:latest镜像被检测出大量安全漏洞
https://hub.docker.com/r/seataio/seata-server/tags
### Ⅱ. Describe what happened
seataio/seata-server:latest镜像存在292个漏洞

If there is an exception, please attach the exception trace:
```
Just paste your stack trace here!
```
### Ⅲ. Describe what you expected to happen
通过镜像部署seata后,上线安全测试检测出292个安全漏洞,涉及组件依赖,我们也不敢升级里面的组件
### Ⅳ. How to reproduce it (as minimally and precisely as possible)
1. 下载镜像
2. 使用trivy进行安全检测
Minimal yet complete reproducer code (or URL to code):
### Ⅴ. Anything else we need to know?
### Ⅵ. Environment:
- JDK version(e.g. `java -version`):
- Seata client/server version:
- Database version:
- OS(e.g. `uname -a`):
- Others:
Contributor guide
Research direction
Start by reviewing the seataio/seata-server:latest image on Docker Hub and the attached Trivy scan to identify what accounts for the 292 findings. Check the repository's image/build configuration and security policy before determining the upgrade scope. Done means the reported vulnerabilities are addressed or their impact and supported upgrade path are documented and validated.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- docker, java
- Domain
- infrastructure, security
- Issue type
- Bug
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 25/100