False positive when a *.deps.json file contains a dependency to a vulnerable package with directory.package.props file and multiple projects
Nessuno ha ancora preso questa issue.
Valutazione
- Difficoltà
- 4/5
- Tempo stimato
- 3-5 giorni
- Idoneità per principianti
- 52/100
Direzione di ricerca
Inizia con il repository per la riproduzione del problema della dipendenza ed esegui l’invocazione Docker Scout di build.ps1. Confronta il modo in cui il main branch e il dep-issue-fixed branch elaborano l’other.csproj referenziato e il relativo *.deps.json con directory.package.props. Il lavoro è completato quando il main branch non segnala più le due vulnerabilità elevate errate e corrisponde al risultato pulito del dep-issue-fixed branch.
Scritto dal modello di indicizzazione a partire dal testo della issue.
Descrizione
Hi,
We have just switched to docker scout to scan our docker images.
We are seeing an issue which seems like issue 93 has returned.
I have made a repoduction repository, it seems to be an issue if there are multiple projects which use a directory.package.props file to manage dependecies. The reproduction also uses dotnet 8 with 10.x.x packages, but that might not be contributing to it.
The code is in this repo https://github.com/chestercodes/docker-scout-playground/tree/main/dependency-issue
There is one difference in that i am using a slightly different base image for the build part, which allows my company laptop to get around the VPN, but the sdk one should work as well.
The docker scout output for the version is included in the run script
The issue seems to stem from the deps file of the referenced project, in this case called other.csproj.
It is not present when the directory.package.props file is remove and the version is specified in each of the csproj files, there is a branch with this case
The differences can be seen in the docker scout invocation, the main branch shows 2 high vulns, which is incorrect, as the updated package is specified in the packages props file.
The branch built image shows no high vulns, which is correct.
- Lingua principale
- Shell
- Stelle
- 454
- Fork
- 134
- Metriche di merge delle PR
- Nessuna PR unita negli ultimi 30g
Guida per i contributori
Nessuna guida per i contributori indicizzata per questo repository
Come iniziare
- Leggi tutta la issue e poi la guida ai contributi del progetto.
- Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
- Fai un fork del repository e lavora su un branch.
- Apri una pull request che faccia riferimento al numero della issue.
Altre issue di docker/scout-cli
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 72/100
-
GO-2026-5932: golang.org/x/crypto reported vulnerable at module level, ignoring import scoping Aperta
Difficoltà 4/5 3-5 giorni Idoneità per principianti 48/100
-
allstar
Difficoltà 2/5 1-3 ore Idoneità per principianti 45/100
-
Difficoltà 4/5 3-5 giorni Idoneità per principianti 48/100
-
panic: nil deref in createVCS() scanning multi-arch image by tag when no attestation sidecar exists Aperta
Difficoltà 4/5 3-5 giorni Idoneità per principianti 64/100
Tutte le issue di docker/scout-cli
Issue simili
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 90/100
danielmiessler/LifeOS#2218 ·
-
docs(agents): strengthen the no-backslash-escaped-backticks rule with an issue-creation example Aperta
Difficoltà 1/5 Meno di un'ora Idoneità per principianti 92/100
-
technical-debt
Difficoltà 2/5 1-3 ore Idoneità per principianti 85/100
ll7/robot_sf_ll7#9560 ·
-
Update ghgrab to 2.1.0 Apertapackage-update
Difficoltà 2/5 1-3 ore Idoneità per principianti 76/100
oSoWoSo/vOid_Community_repOsitory#148 · 1 commento ·
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 68/100