Compare commits
2 Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
9ab158e859 | ||
|
|
e55de85bee |
Vendored
+1
-1
@@ -1,7 +1,7 @@
|
||||
name: "build"
|
||||
on: [push, pull_request]
|
||||
env:
|
||||
TRIVY_VERSION: 0.31.2
|
||||
TRIVY_VERSION: 0.34.0
|
||||
BATS_LIB_PATH: '/usr/lib/'
|
||||
jobs:
|
||||
build:
|
||||
|
||||
+2
-2
@@ -1,5 +1,5 @@
|
||||
FROM ghcr.io/aquasecurity/trivy:0.31.2
|
||||
FROM ghcr.io/aquasecurity/trivy:0.34.0
|
||||
COPY entrypoint.sh /
|
||||
RUN apk --no-cache add bash curl
|
||||
RUN apk --no-cache add bash curl npm
|
||||
RUN chmod +x /entrypoint.sh
|
||||
ENTRYPOINT ["/entrypoint.sh"]
|
||||
|
||||
@@ -13,7 +13,7 @@
|
||||
"id": "DS002",
|
||||
"name": "Misconfiguration",
|
||||
"shortDescription": {
|
||||
"text": "DS002"
|
||||
"text": "Image user should not be \u0026#39;root\u0026#39;"
|
||||
},
|
||||
"fullDescription": {
|
||||
"text": "Running containers with \u0026#39;root\u0026#39; user can lead to a container escape situation. It is a best practice to run containers as non-root users, which can be done by adding a \u0026#39;USER\u0026#39; statement to the Dockerfile."
|
||||
@@ -37,7 +37,7 @@
|
||||
}
|
||||
}
|
||||
],
|
||||
"version": "0.31.2"
|
||||
"version": "0.34.0"
|
||||
}
|
||||
},
|
||||
"results": [
|
||||
@@ -61,6 +61,9 @@
|
||||
"endLine": 1,
|
||||
"endColumn": 1
|
||||
}
|
||||
},
|
||||
"message": {
|
||||
"text": "Dockerfile"
|
||||
}
|
||||
}
|
||||
]
|
||||
|
||||
@@ -28,6 +28,7 @@
|
||||
{
|
||||
"Type": "Dockerfile Security Check",
|
||||
"ID": "DS002",
|
||||
"AVDID": "AVD-DS-0002",
|
||||
"Title": "Image user should not be 'root'",
|
||||
"Description": "Running containers with 'root' user can lead to a container escape situation. It is a best practice to run containers as non-root users, which can be done by adding a 'USER' statement to the Dockerfile.",
|
||||
"Message": "Specify at least 1 USER command in Dockerfile with non-root user as argument",
|
||||
|
||||
@@ -28,6 +28,7 @@
|
||||
{
|
||||
"Type": "Dockerfile Security Check",
|
||||
"ID": "DS002",
|
||||
"AVDID": "AVD-DS-0002",
|
||||
"Title": "Image user should not be 'root'",
|
||||
"Description": "Running containers with 'root' user can lead to a container escape situation. It is a best practice to run containers as non-root users, which can be done by adding a 'USER' statement to the Dockerfile.",
|
||||
"Message": "Specify at least 1 USER command in Dockerfile with non-root user as argument",
|
||||
|
||||
@@ -37,7 +37,7 @@
|
||||
}
|
||||
}
|
||||
],
|
||||
"version": "0.31.2"
|
||||
"version": "0.34.0"
|
||||
}
|
||||
},
|
||||
"results": [
|
||||
|
||||
@@ -75,12 +75,15 @@ Total: 19 (CRITICAL: 19)
|
||||
|
||||
rust-app/Cargo.lock (cargo)
|
||||
===========================
|
||||
Total: 1 (CRITICAL: 1)
|
||||
Total: 2 (CRITICAL: 2)
|
||||
|
||||
ββββββββββββ¬βββββββββββββββββ¬βββββββββββ¬ββββββββββββββββββββ¬ββββββββββββββββ¬ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
|
||||
β Library β Vulnerability β Severity β Installed Version β Fixed Version β Title β
|
||||
ββββββββββββΌβββββββββββββββββΌβββββββββββΌββββββββββββββββββββΌββββββββββββββββΌββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ€
|
||||
β smallvec β CVE-2021-25900 β CRITICAL β 0.6.9 β 0.6.14, 1.6.1 β An issue was discovered in the smallvec crate before 0.6.14 β
|
||||
β openssl β CVE-2018-20997 β CRITICAL β 0.8.3 β 0.10.9 β Use after free in openssl β
|
||||
β β β β β β https://avd.aquasec.com/nvd/cve-2018-20997 β
|
||||
ββββββββββββΌβββββββββββββββββ€ βββββββββββββββββββββΌββββββββββββββββΌββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ€
|
||||
β smallvec β CVE-2021-25900 β β 0.6.9 β 1.6.1, 0.6.14 β An issue was discovered in the smallvec crate before 0.6.14 β
|
||||
β β β β β β and 1.x... β
|
||||
β β β β β β https://avd.aquasec.com/nvd/cve-2021-25900 β
|
||||
ββββββββββββ΄βββββββββββββββββ΄βββββββββββ΄ββββββββββββββββββββ΄ββββββββββββββββ΄ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
|
||||
|
||||
@@ -75,12 +75,15 @@ Total: 19 (CRITICAL: 19)
|
||||
|
||||
rust-app/Cargo.lock (cargo)
|
||||
===========================
|
||||
Total: 4 (CRITICAL: 4)
|
||||
Total: 5 (CRITICAL: 5)
|
||||
|
||||
βββββββββββββ¬βββββββββββββββββ¬βββββββββββ¬ββββββββββββββββββββ¬ββββββββββββββββ¬ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
|
||||
β Library β Vulnerability β Severity β Installed Version β Fixed Version β Title β
|
||||
βββββββββββββΌβββββββββββββββββΌβββββββββββΌββββββββββββββββββββΌββββββββββββββββΌββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ€
|
||||
β rand_core β CVE-2020-25576 β CRITICAL β 0.4.0 β 0.3.1, 0.4.2 β An issue was discovered in the rand_core crate before 0.4.2 β
|
||||
β openssl β CVE-2018-20997 β CRITICAL β 0.8.3 β 0.10.9 β Use after free in openssl β
|
||||
β β β β β β https://avd.aquasec.com/nvd/cve-2018-20997 β
|
||||
βββββββββββββΌβββββββββββββββββ€ βββββββββββββββββββββΌββββββββββββββββΌββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ€
|
||||
β rand_core β CVE-2020-25576 β β 0.4.0 β 0.3.1, 0.4.2 β An issue was discovered in the rand_core crate before 0.4.2 β
|
||||
β β β β β β for Rust.... β
|
||||
β β β β β β https://avd.aquasec.com/nvd/cve-2020-25576 β
|
||||
βββββββββββββΌβββββββββββββββββ€ βββββββββββββββββββββΌββββββββββββββββΌββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ€
|
||||
@@ -92,7 +95,7 @@ Total: 4 (CRITICAL: 4)
|
||||
β β β β β β for Rust.... β
|
||||
β β β β β β https://avd.aquasec.com/nvd/cve-2019-15554 β
|
||||
β ββββββββββββββββββ€ β βββββββββββββββββΌββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ€
|
||||
β β CVE-2021-25900 β β β 0.6.14, 1.6.1 β An issue was discovered in the smallvec crate before 0.6.14 β
|
||||
β β CVE-2021-25900 β β β 1.6.1, 0.6.14 β An issue was discovered in the smallvec crate before 0.6.14 β
|
||||
β β β β β β and 1.x... β
|
||||
β β β β β β https://avd.aquasec.com/nvd/cve-2021-25900 β
|
||||
βββββββββββββ΄βββββββββββββββββ΄βββββββββββ΄ββββββββββββββββββββ΄ββββββββββββββββ΄ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
|
||||
|
||||
@@ -69,7 +69,6 @@
|
||||
]
|
||||
},
|
||||
"Match": "export GITHUB_PAT=****************************************",
|
||||
"Deleted": false,
|
||||
"Layer": {}
|
||||
}
|
||||
]
|
||||
|
||||
@@ -60,6 +60,7 @@
|
||||
"Vulnerabilities": [
|
||||
{
|
||||
"VulnerabilityID": "CVE-2021-36159",
|
||||
"PkgID": "apk-tools@2.10.6-r0",
|
||||
"PkgName": "apk-tools",
|
||||
"InstalledVersion": "2.10.6-r0",
|
||||
"FixedVersion": "2.10.7-r0",
|
||||
|
||||
Reference in New Issue
Block a user