Uploaded image for project: 'Project Quay'
  1. Project Quay
  2. PROJQUAY-2880

clair shows vulnerable packages from pyup.io which are actually fixed by RHSA

XMLWordPrintable

    • False
    • False
    • Quay Enterprise

      Clair shows false positive on packages in pyup.io which have actually been resolved by more recent RHSAs.

      Case in point - refer to attached image:

      The python3-urllib3 package is included in nodejs-14 built on ubi8, here:

      https://catalog.redhat.com/software/containers/ubi8/nodejs-14/5ed7887dd70cc50e69c2fabb?container-tabs=packages

              Unassigned Unassigned
              rhn-support-dyocum Daniel Yocum
              Votes:
              0 Vote for this issue
              Watchers:
              4 Start watching this issue

                Created:
                Updated:
                Resolved: