Uploaded image for project: 'Project Quay'
  1. Project Quay
  2. PROJQUAY-2880

clair shows vulnerable packages from pyup.io which are actually fixed by RHSA

XMLWordPrintable

    • False
    • False
    • Quay Enterprise
    • 0

      Clair shows false positive on packages in pyup.io which have actually been resolved by more recent RHSAs.

      Case in point - refer to attached image:

      The python3-urllib3 package is included in nodejs-14 built on ubi8, here:

      https://catalog.redhat.com/software/containers/ubi8/nodejs-14/5ed7887dd70cc50e69c2fabb?container-tabs=packages

            Unassigned Unassigned
            rhn-support-dyocum Daniel Yocum
            Votes:
            0 Vote for this issue
            Watchers:
            5 Start watching this issue

              Created:
              Updated:
              Resolved: