-
Notifications
You must be signed in to change notification settings - Fork 977
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Crticial vulnerabilities on netshoot image #111
Comments
please re run test with latest image ( v0.7) as I upgraded to alpine 3.16 |
It seems most of these are fixed 👍
|
Let's maybe consider configuring Dependabot for keeping dependency like a base image up to date |
@programmer04 any chance you can submit a PR ? |
I can also add some security scanning stuff in the pipeline. I can file an issue for this if you want. |
Sure, I've just created the PR @nicolaka #113. I think that adding security scanning is a good idea @Dentrax (e.g. once a day to detect the newest reported vulnerabilities)! GitHub unfortunately does not support Docker images in their dependency graph so security vulnerabilities are not reported automatically. |
I scanned netshoot image with Gyrpe and it found some critical vulns. Are there any plan to mitigate these? It would be nice to have a scheduled action that scans the image for vulns.
The text was updated successfully, but these errors were encountered: