Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

CVE(s) found #2247

Closed
github-actions bot opened this issue Aug 12, 2024 · 2 comments · Fixed by #2246
Closed

CVE(s) found #2247

github-actions bot opened this issue Aug 12, 2024 · 2 comments · Fixed by #2246
Labels
cve status/ready Issue ready to be worked on. type/bug Issue that reports an unexpected behaviour.
Milestone

Comments

@github-actions
Copy link

Latest buildpacksio/pack v0.35.1 triggered CVE(s) from Grype. For further details, see: https://github.com/buildpacks/pack/actions/runs/10344879230

@github-actions github-actions bot added cve status/triage Issue or PR that requires contributor attention. type/bug Issue that reports an unexpected behaviour. labels Aug 12, 2024
@natalieparellano
Copy link
Member

The scan found 4 CVEs, the first two are false positives and should be addressed by #2250.

The second two (CVE-2024-41110, GHSA-v23v-6jw2-98fq) appear to be the same vulnerability and are non-impactful as pack uses only the docker client library. We can probably silence these with a dependency bump, so I didn't add it to the ignore file.

@natalieparellano natalieparellano added status/ready Issue ready to be worked on. and removed status/triage Issue or PR that requires contributor attention. labels Aug 15, 2024
@natalieparellano natalieparellano added this to the 0.36.0 milestone Aug 15, 2024
@jjbustamante
Copy link
Member

@natalieparellano I think this one will be solved with #2246

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
cve status/ready Issue ready to be worked on. type/bug Issue that reports an unexpected behaviour.
Projects
None yet
2 participants