Uploaded image for project: 'Project Quay'
  1. Project Quay
  2. PROJQUAY-1822

CVE-2019-20149 quay-registry-container: nodejs-kind-of: ctorName in index.js allows external user input to overwrite certain internal attributes [quay-3.6]

    XMLWordPrintable

Details

    • 0

    Description

      At the moment the shipped image includes all the development JavaScript dependencies. This causes false-positives to appear in scans of the image, such as PROJQUAY-1747.

      Ideally we should make the 'npm install', and 'npm run build' steps occur in an earlier stage, and the output of the npm run build only should be included in the final image. Ie. only the static folder.

      Attachments

        Issue Links

          Activity

            People

              tomckay@redhat.com Thomas Mckay
              rhn-support-jshepher Jason Shepherd
              Votes:
              0 Vote for this issue
              Watchers:
              2 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved: