-
Bug
-
Resolution: Not a Bug
-
Major
-
None
-
clair-4.3.3
Clair shows false positive on packages in pyup.io which have actually been resolved by more recent RHSAs.
Case in point - refer to attached image:
- clair-4.3.x says python3-urllib3-1.24.2-5.el8.noarch is vulnerable according to pyup.io-38834.
- The vulnerability was addressed in https://access.redhat.com/errata/RHSA-2021:1631, build #5 of python3-urllib3-1.24.2 is NOT vulnerable.
The python3-urllib3 package is included in nodejs-14 built on ubi8, here:
- is related to
-
PROJQUAY-4023 Clair interprets scan results instead of just delivering them
- New
-
PROJQUAY-1279 Allow users silence specific CVEs per repo / per org
- In Progress
-
PROJQUAY-4994 Allow users silence specific CVEs per repo / per org
- Closed
- relates to
-
PROJQUAY-3294 Python rpm scans produces false positive on rhel/ubi based images
- Closed