While doing a some checks on the container grades for OSP 17.0 we noticed the catalog is reporting a 'B' grade for one of our images [1]. Digging further into the linked RHEL advisories we noticed that they list git[2] from 9.1 instead of the 9.0 EUS versions as expected.
Please let us know if we can provide any more information to help get things corrected.
[1] https://catalog.redhat.com/software/containers/registry/registry.access.redhat.com/repository/rhosp-rhel9/openstack-aodh-base?tag=17.0.1-7&push_date=1677614335000&container-tabs=security
[2] https://access.redhat.com/errata/RHSA-2023:0611
- is related to
-
CLAIRDEV-45 OSBS layers contain insufficient information to make CPE assertions
- To Do
- is triggered by
-
CLAIRDEV-41 Examine dnf database in addition to rpm database
- To Do