Possible issue with pip detection
@cdupuis 已经在做这个了。
开始于 2024年6月6日。
评估
这个 Issue 还没有评估数据。
描述
I fully understand that pip has a weird vulnerability cve-2018-20225 but even if you uninstall pip and pip3 docker scout is still showing this vulnerability. My question is does any package installed by pip still cause this cve? I thought it was only the pip package its self due to the way it could install packages incorrectly using the --extra-index-url flag.
- 主要语言
- Shell
- 星标
- 455
- 派生
- 134
- PR 合并指标
- 30 天内没有已合并 PR
环境准备
这个项目没有提供开发容器、Dockerfile 或贡献指南,环境需要你自己搭建:先看它的 README,通用步骤见我们的新手贡献指南。
从这里开始
- 先读完整个 Issue,再读项目的贡献指南。
- 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
- Fork 仓库,在一个分支上完成修改。
- 提交 Pull Request,并在描述里引用这个 Issue 编号。
docker/scout-cli 的其他 Issue
-
难度 2/5 1-3 小时 新手友好度 72/100
-
难度 4/5 3-5 天 新手友好度 48/100
-
allstar
难度 2/5 1-3 小时 新手友好度 45/100
-
难度 4/5 3-5 天 新手友好度 48/100
-
panic: nil deref in createVCS() scanning multi-arch image by tag when no attestation sidecar exists未关闭
难度 4/5 3-5 天 新手友好度 64/100
相似的 Issue
-
type: bug
难度 2/5 1-3 小时 新手友好度 67/100
catppuccin/kde#152 ·
-
update-request
难度 2/5 1-3 小时 新手友好度 75/100
msys2/MINGW-packages#32008 ·
维护者通常 1 天内回复
-
bot-found bug priority: P3
难度 2/5 1-3 小时 新手友好度 84/100
madenvel/KalinkaPlayer#179 ·
-
难度 2/5 1-3 小时 新手友好度 88/100
维护者通常 1 天内回复
-
documentation
难度 2/5 1-3 小时 新手友好度 72/100