Uploaded image for project: 'Project Quay'
  1. Project Quay
  2. PROJQUAY-9223

Audit and update stale third-party application dependencies to mitigate known vulnerabilities.

XMLWordPrintable

    • Icon: Task Task
    • Resolution: Can't Do
    • Icon: Normal Normal
    • None
    • None
    • quay.io
    • False
    • Hide

      None

      Show
      None
    • False

      *Issue:* An internal audit discovered that several application components rely on outdated third-party libraries, some of which have known security vulnerabilities.
      *Corrective Action:* Integrate a dependency scanning tool like Snyk or Dependabot into the CI pipeline. A policy should be created to automatically generate tickets for any high or critical severity vulnerabilities found.
      *Result:* This will improve the application's overall security posture by ensuring components are not exposed to previously discovered vulnerabilities.

              Unassigned Unassigned
              doconnor@redhat.com Dave O'Connor
              Votes:
              0 Vote for this issue
              Watchers:
              1 Start watching this issue

                Created:
                Updated:
                Resolved: