-
-
Notifications
You must be signed in to change notification settings - Fork 63
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
docker image scan reports issues #823
Comments
What tool are you using to generate this report? If you send me a list of CVEs, I can check if they impact Kodiak. |
Running
Of course I'm only looking at the python specific output, if you grab the entire output of that tool you get 15,000 lines of output aka garbage. I think this tool suffers from a similar problem to |
Digging into the output a bit more, here's the output in a less verbose form where the key is the package name and the value is the number of CVEs associated with it.
|
Hi @sbdchd, I got a different output using this version.
|
Could be a first improvement: #796 |
The docker image (cdignam/kodiak:v0.52.0) mentioned in the docs for selfhosting does not have a great reputation when it comes to security.
A trivy scan shows 199 critical issues in the latest release.
It seems that new versions add more critical cve's, (v0.50.0 had 157).
What is going on here?
The text was updated successfully, but these errors were encountered: