cube-js/cube

Docker scan for V0.32 reported 4 critical vulnerabilities (75 in total) - SOC2 T2 assessment

オープン

#6,340 opened on 2023/03/23

 (3 件のコメント) (1 件のリアクション) (1 人の担当者)Rust (1,965 件のフォーク)batch import
help wantedsecurity

Repository metrics

Stars
 (19,563 個のスター)
PR merge metrics
 (PR metrics pending)

説明

Describe the bug We are in the process of a SOC2 T2 audit. Part of the process is a vulnerability assessment of all images, and containers.

We ran a static scan on the latest (0.32) Docker image version. Based on the scans from Docker that latest version has 75 vulnerabilities, and 4 of those are critical. See image below.

Most likely, these vulnerabilities will have an impact on other organizations aldo running formal security audits. As per our SOC2, critical vulnerabilities have an SLA for resolution of 14 days.

This issue was communicated via Slack. @keydunov asked us to file this Github issue.

To Reproduce Open Docker Desktop and run scan

Screenshot 2023-03-23 at 9 51 23 AM

Version: V0.32.14

コントリビューターガイド