-
Notifications
You must be signed in to change notification settings - Fork 295
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
fix(security): vulnerabilities found in example-carbon-accounting #2062
Comments
P4 because this container image is not meant to be used in production. |
@petermetz please assign this to me. Thank you |
CVE-2021-39167, CVE-2021-41264, CVE-2021-46320 are currently fixed in our package version. CVE-2022-21676 is currently fixed in our package version. CVE-2021-3918 is currently fixed in our package version. CVE-2021-30246 is currently fixed in our package version. CVE-2022-24771, CVE-2022-24772 requires 1.1.0 release. Depends on #2054 CVE-2021-23358 was already fixed in PR #1816. Requires 1.1.0 release. Depends on #2054 |
Could we possible modify vulnerability tables to include a local ID, such as this?
Will be easier to cross reference what isn't an issue and what is. |
Fixes hyperledger-cacti#2062 Signed-off-by: zondervancalvez <[email protected]>
Fixes hyperledger-cacti#2062 Signed-off-by: zondervancalvez <[email protected]>
Fixes hyperledger-cacti#2062 Signed-off-by: zondervancalvez <[email protected]>
Fixes hyperledger-cacti#2062 Signed-off-by: zondervancalvez <[email protected]>
Fixes hyperledger-cacti#2062 Signed-off-by: zondervancalvez <[email protected]>
Fixes hyperledger-cacti#2062 Signed-off-by: zondervancalvez <[email protected]>
Fixes hyperledger-cacti#2062 Signed-off-by: micoferdinand98 <[email protected]>
Fixes hyperledger-cacti#2062 Signed-off-by: micoferdinand98 <[email protected]>
Fixes hyperledger-cacti#2062 Signed-off-by: micoferdinand98 <[email protected]>
Fixes hyperledger-cacti#2062 Signed-off-by: micoferdinand98 <[email protected]>
Fixes hyperledger-cacti#2062 Signed-off-by: micoferdinand98 <[email protected]>
Fixes hyperledger-cacti#2062 Signed-off-by: micoferdinand98 <[email protected]>
Hello @petermetz I tried to scan the latest available version for carbon accounting backend which is v1.1.3. The result of the scan shows that some of the vulnerabilities detected in the packages in the of carbon accounting backend we have already the fixed version or greater than based on checking the latest changes in our package.json with our latest commit. So I think we just need to issue a new release for carbon accounting backend to be able to see if there are still remaining vulnerabilities with the latest changes that we have and so that we would scan the latest and updated version. |
@aldousalvarez Gotcha, I marked it as dependent on the issuance of the new release which will then allow you to run the scan against the latest npm package with the updated dependencies. |
@aldousalvarez I've managed to publish v2.0.0-alpha.1 to npm for all the packages, please re-test with those! |
@petermetz Based on the trivy scan on version 1.1.3 the vulnerabilities has a Total of 16 (HIGH: 14, CRITICAL: 2) After testing the version 2.0.0-alpha.1 after this scan the total remaining vulnerabilities is After checking the results based on the latest scan (version 2.0.0-alpha.1) the package.json of carbon-accounting-backend And the rest cannot be found on the package.json so it cannot be fixed or upgraded |
Depends on #2718 Waiting for that issue to be merged and then a new package version release that has the updated dependencies which uses the fixed version of http-cache-semantics |
@aldousalvarez FYI: |
Primary Changes ---------------- 1. Modified the Dockerfile to use the updated versions of the packages being used 2. Modified the supervisord.conf to use the correct path because it has changed after updating the versions Fixes hyperledger-cacti#2062 Signed-off-by: aldousalvarez <[email protected]>
Primary Changes ---------------- 1. Modified the Dockerfile to use the updated versions of the packages being used 2. Modified the supervisord.conf to use the correct path because it has changed after updating the versions Fixes hyperledger-cacti#2062 Signed-off-by: aldousalvarez <[email protected]>
Primary Changes ---------------- 1. Modified the Dockerfile to use the updated versions of the packages being used 2. Modified the supervisord.conf to use the correct path because it has changed after updating the versions Fixes hyperledger-cacti#2062 Signed-off-by: aldousalvarez <[email protected]>
Primary Changes ---------------- 1. Modified the Dockerfile to use the updated versions of the packages being used 2. Modified the supervisord.conf to use the correct path because it has changed after updating the versions Fixes hyperledger-cacti#2062 Signed-off-by: aldousalvarez <[email protected]>
Primary Changes ---------------- 1. Modified the Dockerfile to use the updated versions of the packages being used 2. Modified the supervisord.conf to use the correct path because it has changed after updating the versions Fixes hyperledger-cacti#2062 Signed-off-by: aldousalvarez <[email protected]>
Primary Changes ---------------- 1. Modified the Dockerfile to use the updated versions of the packages being used 2. Modified the supervisord.conf to use the correct path because it has changed after updating the versions Fixes hyperledger-cacti#2062 Signed-off-by: aldousalvarez <[email protected]>
Primary Changes ---------------- 1. Modified the Dockerfile to use the updated versions of the packages being used 2. Modified the supervisord.conf to use the correct path because it has changed after updating the versions Fixes hyperledger-cacti#2062 Signed-off-by: aldousalvarez <[email protected]>
Primary Changes ---------------- 1. Modified the Dockerfile to use the updated versions of the packages being used 2. Modified the supervisord.conf to use the correct path because it has changed after updating the versions Fixes hyperledger-cacti#2062 Signed-off-by: aldousalvarez <[email protected]>
Primary Changes ---------------- 1. Modified the Dockerfile to use the updated versions of the packages being used 2. Modified the supervisord.conf to use the correct path because it has changed after updating the versions Fixes hyperledger-cacti#2062 Signed-off-by: aldousalvarez <[email protected]>
Primary Changes ---------------- 1. Modified the Dockerfile to use the updated versions of the packages being used 2. Modified the supervisord.conf to use the correct path because it has changed after updating the versions Fixes #2062 Signed-off-by: aldousalvarez <[email protected]>
Primary Changes ---------------- 1. Modified the Dockerfile to use the updated versions of the packages being used 2. Modified the supervisord.conf to use the correct path because it has changed after updating the versions Fixes #2062 Signed-off-by: aldousalvarez <[email protected]>
Primary Changes ---------------- 1. Modified the Dockerfile to use the updated versions of the packages being used 2. Modified the supervisord.conf to use the correct path because it has changed after updating the versions Fixes hyperledger-cacti#2062 Signed-off-by: aldousalvarez <[email protected]>
List of vulnerabilities found in example-carbon-accounting image during Azure Container scan.
The text was updated successfully, but these errors were encountered: