-
-
Notifications
You must be signed in to change notification settings - Fork 202
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Gospatial/tegola:latest docker image haves security issues #1000
Comments
@fjrsaracho thanks for the report! I will get this updated for the next release. This makes me think we should implement weekly code scanning to keep on top of these vulns. That way it's not just pushes that trigger the scan. |
@ARolek Investigating a bit seems to be easy to implement there is already an action supported by aquasecurity, check it out here: https://github.com/aquasecurity/trivy-action May I ask why are you uploading vendors? |
Do you know if Trivy is free for open source? I have only encountered it commercially.
As in, why are we vendoring our dependancies? This is a long debated project, but generally speaking I want the project to be buildable without needing to fetch anything externally. |
Hello! Not sure if it fits for you as a real "open-source" |
Hello,
Scanning Gospatial/tegola:latest with trivy scan is reporting security issue marked as critical CVE-2024-24790
It is already fixed on stdlib >1.21.11
The text was updated successfully, but these errors were encountered: