Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Bump dependencies to resolve CVEs in napa branch #1583

Open
cloudxxx8 opened this issue May 10, 2024 · 0 comments
Open

Bump dependencies to resolve CVEs in napa branch #1583

cloudxxx8 opened this issue May 10, 2024 · 0 comments

Comments

@cloudxxx8
Copy link
Member

Some old depedencies should be upgraded to resolve CVEs

cloud@cloud-VirtualBox:~/EdgeX/edgex-compose$ docker scout cves --format only-packages --only-vuln-packages edgexfoundry/app-service-configurable:3.1.0

    i New version 1.8.0 available (installed version is 1.7.0) at https://github.com/docker/scout-cli

    ✓ Image stored for indexing

    ✓ Indexed 84 packages

    ✗ Detected 6 vulnerable packages with a total of 23 vulnerabilities



              Name               Version    Type            Vulnerabilities            

──────────────────────────────────────────────────────────────────────────────────────────

  github.com/go-jose/go-jose/v3  3.0.0     golang     0C     0H     2M     0L     1?   

  golang.org/x/crypto            0.14.0    golang     0C     0H     1M     0L          

  golang.org/x/net               0.17.0    golang     0C     0H     1M     0L          

  google.golang.org/protobuf     1.30.0    golang     0C     0H     1M     0L          

  openssl                        3.1.4-r1  apk        0C     0H     2M     0L     2?   

  stdlib                         1.21.0    golang     0C     4H     4M     0L     6?   

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
Status: New Issues
Development

No branches or pull requests

1 participant