Uploaded image for project: 'OpenShift Builds'
  1. OpenShift Builds
  2. BUILD-1192

s2i: Audit use of golang x/crypto libraries

XMLWordPrintable

    • Icon: Spike Spike
    • Resolution: Done
    • Icon: Critical Critical
    • s2i-1.5
    • s2i-1.4
    • source-to-image
    • None
    • 1
    • False
    • Hide

      None

      Show
      None
    • False
    • Release Note Not Required
    • 2
    • Builds Sprint #18, Builds Sprint #19
    • 2

      Spike Story

      Audit the use of golang x/crypto libraries in source-to-image. Some use is okay, some use is not. See x/crypto usage notes.

      Acceptance Criteria

      • Review s2i dependencies that reference the Golang x/crypto libraries
      • Determine if any code paths import disallowed modules
      • If a disallowed module is reachable, assess if its use can be blocked.

              rh-ee-asatyam Ayush Satyam
              adkaplan@redhat.com Adam Kaplan
              Votes:
              0 Vote for this issue
              Watchers:
              2 Start watching this issue

                Created:
                Updated:
                Resolved: