Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

25 of 134 components are vulnerable?! #374

Closed
aboettger opened this issue Apr 4, 2017 · 2 comments
Closed

25 of 134 components are vulnerable?! #374

aboettger opened this issue Apr 4, 2017 · 2 comments

Comments

@aboettger
Copy link

Can you explain this at least? Transparency is everything.
https://hub.docker.com/r/library/node/tags/7/

@chorrell
Copy link
Contributor

chorrell commented Apr 4, 2017

See also:

docker-library/official-images#2740
#219
#195 (comment)

@chorrell
Copy link
Contributor

chorrell commented Apr 4, 2017

The TLDR; is that the Docker Hubs reporting of vulnerabilities isn't entirely accurate.

CVE-2014-9761 for instance (as noted in docker-library/official-images/issues/2740) is marked as a "Minor issue" by the Debian Security team. See https://security-tracker.debian.org/tracker/CVE-2014-9761

CVE-2016-5180 was patched directly in node with nodejs/node#8849

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants