Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Adding sbom_generation.yml for enabling vulnerability scan by GCAS tool #454

Open
wants to merge 2 commits into
base: main
Choose a base branch
from

Conversation

LesiaChaban
Copy link
Member

Hi repo maintainers,
The OGHO team scans all Oracle GitHub repos for vulnerabilities using GCAS tool. Unfortunately, the automatic scan for your repo failed, so the GCAS team recommends to create a custom SBOM file in this case. This PR adds such a file to this repo.
Can you please review and approve the PR?

@oracle-contributor-agreement oracle-contributor-agreement bot added the OCA Verified All contributors have signed the Oracle Contributor Agreement. label Feb 18, 2025
@LesiaChaban LesiaChaban changed the title Adding sbom_generation.yml for enabling vulnerability scan by GCAS toolAdd files via upload Adding sbom_generation.yml for enabling vulnerability scan by GCAS tool Feb 18, 2025
@cjbj
Copy link
Member

cjbj commented Feb 19, 2025

@LesiaChaban I am concerned about the security vulnerabilities in the version of Node.js used: https://www.cvedetails.com/vulnerability-list/vendor_id-12113/product_id-30764/version_id-1274255/Nodejs-Node.js-16.14.2.html

@LesiaChaban
Copy link
Member Author

@cjbj let me check it with the GCAS Team

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
OCA Verified All contributors have signed the Oracle Contributor Agreement.
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants