Uploaded image for project: 'Project Quay'
  1. Project Quay
  2. PROJQUAY-6622

claircore: gobin: does not detect several Go vulnerabilities

XMLWordPrintable

      For example quay.io/

      The scanner binary depends on golang.org/x/net@v0.14.0 which is definitely susceptible to https://osv.dev/vulnerability/GHSA-4374-p667-p6c8

      The issue is likely due to Claircore's handling of OSV SEMVER ecosystems when Introduced is 0.

              rtannenb@redhat.com Ross Tannenbaum
              rtannenb@redhat.com Ross Tannenbaum
              Votes:
              0 Vote for this issue
              Watchers:
              2 Start watching this issue

                Created:
                Updated:
                Resolved: