higlass / higlass/higlass-docker

security (CVEs) issues - 4 critical and 11 high - most fixed by upgrading components

Open
#183 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
Shell
Stars
34
Forks
16
PR merge metrics
No merged PRs in 30d

Description

[higlass-docker-scan.html.txt](https://github.com/higlass/higlass-docker/files/9974055/higlass-docker-scan.html.txt)

You can find the attached Aqua Scan report - remove the .txt outer extension and open in a browser.
Under Vulnerabilities you can see multiple Critical and High issues related to out of date packages / libraries.
Other issues are based on this being an Ubuntu image (I think you can find alpine base images that are secure).

Critical look to be Django (fix 2.2.26 --> 2.2.28), Werkzeug (2.0.3 --> 2.2.1) , and joblib (1.1.0 --> 1.2.0)
High are a mix of Ubuntu issues and some are pypi or javascript components (mistune)
Happy to re-scan for you.

Contributor guide

No contributing guide indexed for this repository

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.