-
Notifications
You must be signed in to change notification settings - Fork 2
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Upgrade dependencies 2023-11-27 #5723
Comments
|
|
Above is a screenshot of the most recent report with findings removed for images we don't use inside the boundary. It's OK to post image vulnerability findings for Docker images. Which images we use is publicly available information (source code). Their vulnerabilities are also publicly listed on Dockerhub. |
The next report should sort the rows by severity and number of affected images. Triaging to see what this would entail. |
Lastly, it is a bit silly to just ignore checklist items that one doesn't have permissions for. Obviously, something needs to be done. The assignee of the ticket is responsible for that. |
make format
README.md
make test
requirements*.txt
from open Dependabot PRs, one commit per PRprod
may not use the latest image) …… to next major Docker versionanvilprod
on this issueanvilprod
The text was updated successfully, but these errors were encountered: