Uploaded image for project: 'Project Quay'
  1. Project Quay
  2. PROJQUAY-1822

CVE-2019-20149 quay-registry-container: nodejs-kind-of: ctorName in index.js allows external user input to overwrite certain internal attributes [quay-3.6]

XMLWordPrintable

      At the moment the shipped image includes all the development JavaScript dependencies. This causes false-positives to appear in scans of the image, such as PROJQUAY-1747.

      Ideally we should make the 'npm install', and 'npm run build' steps occur in an earlier stage, and the output of the npm run build only should be included in the final image. Ie. only the static folder.

              tomckay@redhat.com Thomas Mckay (Inactive)
              rhn-support-jshepher Jason Shepherd
              Votes:
              0 Vote for this issue
              Watchers:
              2 Start watching this issue

                Created:
                Updated:
                Resolved: