spiffe/spire

CVEs in dependencies, support for VEX?

Open

#6.054 aberto em 7 de mai. de 2025

Ver no GitHub
 (10 comments) (0 reactions) (0 assignees)Go (631 forks)auto 404
help wantedpriority/backlogunscoped

Métricas do repositório

Stars
 (2.443 stars)
Métricas de merge de PR
 (Métricas PR pendentes)

Description

Hello,

I was wondering what's the project's stance on regular security scans for dependencies using tools like trivy. Forgive me if I missed a documentation about it. I was hoping for the next release (1.12.1) to include some bumped dependency versions to get rid of CVEs (for a while) but that is apparently not part of your release process.

Since this is as recurring issue, maybe you would be open to publishing a VEX for CVEs? So far I went with judging and allowlisting CVEs on my own, but it can be hard sometimes for someone who is not the author of the application (and I guess not all users have the dev capabilities to read the code at all). I also imagine it to be more effective to run some scan on your own instead of waiting for users to create issues for each finding.

Looking forward to find out about your view on this!

Guia do colaborador