Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[🚀 Feature]: Patching OS packages for vulnerabilities #1943

Closed
amardeep2006 opened this issue Sep 13, 2023 · 5 comments
Closed

[🚀 Feature]: Patching OS packages for vulnerabilities #1943

amardeep2006 opened this issue Sep 13, 2023 · 5 comments

Comments

@amardeep2006
Copy link
Contributor

Feature and motivation

I recently scanned the images for security vulnerabilities and found many OS packages having High vulnerabilities.
I had to extend all the docker images to pass the security scan in organization.
Is there some reason we are not using apt-get upgrade -yq in Dockerfiles ?

I can raise PR if apt-get upgrade is acceptable solution for OS related vulnerabilities.

Usage example

Many enterprise want to scan docker images before using.

@github-actions
Copy link

@amardeep2006, thank you for creating this issue. We will troubleshoot it as soon as we can.


Info for maintainers

Triage this issue by using labels.

If information is missing, add a helpful comment and then I-issue-template label.

If the issue is a question, add the I-question label.

If the issue is valid but there is no time to troubleshoot it, consider adding the help wanted label.

If the issue requires changes or fixes from an external project (e.g., ChromeDriver, GeckoDriver, MSEdgeDriver, W3C), add the applicable G-* label, and it will provide the correct link and auto-close the issue.

After troubleshooting the issue, please add the R-awaiting answer label.

Thank you!

@diemol
Copy link
Member

diemol commented Sep 13, 2023

Sure, happy to review a PR for that.

@amardeep2006
Copy link
Contributor Author

Thanks , I will try to raise one this weekend.

@amardeep2006
Copy link
Contributor Author

#1950 fixed this

Copy link

github-actions bot commented Dec 9, 2023

This issue has been automatically locked since there has not been any recent activity after it was closed. Please open a new issue for related bugs.

@github-actions github-actions bot locked and limited conversation to collaborators Dec 9, 2023
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Projects
None yet
Development

No branches or pull requests

2 participants