Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

vulnerabilities in every docker image #764

Closed
kostapsimoulis opened this issue May 30, 2018 · 3 comments
Closed

vulnerabilities in every docker image #764

kostapsimoulis opened this issue May 30, 2018 · 3 comments

Comments

@kostapsimoulis
Copy link

The docker scanned images in docker hub are reporting severe vulnerabilities in almost every image. Not sure if this is a false positive but I believe it needs to be investigated.

I am attaching screenshot to demonstrate the issue.

screen shot 2018-05-30 at 11 25 33 am

screen shot 2018-05-30 at 11 24 59 am

@kostapsimoulis
Copy link
Author

It looks like most of them are related to debian:jessie but it looks embarrassing that there are so many vulnerabilities. Perhaps someone can investigate further if this is a false positive and give a clear explanation.

@chorrell
Copy link
Contributor

chorrell commented Jun 5, 2018

This comes up from time to time. See also:

#374
docker-library/official-images#2740
#219
#195 (comment)

The TLDR; is that the Docker Hubs reporting of vulnerabilities isn't entirely accurate.

For example CVE-2017-16997 is flagged as "no-dsa"/"Minor issue" by the Debian Security team and are not actively fixing it

@nschonni
Copy link
Member

Closing as the Security reporting instructions was added to https://github.com/nodejs/docker-node/blob/master/SECURITY.md

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants