Uploaded image for project: 'Project Quay'
  1. Project Quay
  2. PROJQUAY-6622

claircore: gobin: does not detect several Go vulnerabilities

XMLWordPrintable

    • 0

      For example quay.io/

      The scanner binary depends on golang.org/x/net@v0.14.0 which is definitely susceptible to https://osv.dev/vulnerability/GHSA-4374-p667-p6c8

      The issue is likely due to Claircore's handling of OSV SEMVER ecosystems when Introduced is 0.

            rtannenb@redhat.com Ross Tannenbaum
            rtannenb@redhat.com Ross Tannenbaum
            Votes:
            0 Vote for this issue
            Watchers:
            2 Start watching this issue

              Created:
              Updated:
              Resolved: