aws / aws/aws-xray-daemon

Add alpine tag for container

Open
#164 4 comments 0 reactions 0 assignees View on GitHub
Dominant language
Go
Stars
193
Forks
73
Avg merge
2d 7h
Merged PRs (30d)
3

Description

Using Amazon 2 will detected the CVEs by [Trivy](https://github.com/aquasecurity/trivy)

- CVE-2021-3177
- CVE-2016-2183
- CVE-2019-20907
- CVE-2020-26116

Although we are not using python, it still exist in the OS. Could we add more tags for different OS or delete some unused packages(e.g. `usr/lib64/python2.7/lib-dynload/Python-2.7.18-py2.7.egg-info`) when building image?

Contributor guide

Open the contributing guide

Research direction

Start by locating the container-image build configuration and existing image tags, then inspect how the Amazon 2 base image and packages are selected. Determine whether adding an Alpine tag or removing unused packages is supported, and verify the resulting image against the listed Trivy CVEs.

Written by the indexing model from the issue text.

Assessment

Tech stack
docker, linux
Domain
devops, security
Issue type
Feature
Difficulty
3/5
Estimated time
1-2 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.