docToolchain / docToolchain/docker-image

197 vulnerabilities detected in 3.1.2

Open
#48 2 comments 1 reaction 0 assignees View on GitHub
Dominant language
Groovy
Stars
4
Forks
15
PR merge metrics
No merged PRs in 30d

Description

Dear devs,

can you please consider using a dependency bot like renovate to update the dependencies?

Due to a corporate rule, I mirror the docker image on our internal registry. We are using Quay and it has an inbuilt security scanner. Unfortunately, there is no reporting feature, so I am pasting it here directly in. Please note that the report is based on the image tag `v3.1.2`. Quay fixes most of the dependencies automatically by introducing new docker layers with updated package versions, but I guess it will help everyone if you do the fixes directly in the image.

# Summary
Quay Security Scanner has detected 197 vulnerabilities.
Patches are available for 193 vulnerabilities.
24 Critical-level vulnerabilities.
88 High-level vulnerabilities.
55 Medium-level vulnerabilities.
25 Low-level vulnerabilities.
5 Unknown-level vulnerabilities.

## Attachment with details
[Sec_report.pdf](https://github.com/docToolchain/docker-image/files/13393135/Sec_report.pdf)

Contributor guide

No contributing guide indexed for this repository

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.