Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Addresses open CVEs #197

Merged
merged 1 commit into from
Dec 27, 2024
Merged

Addresses open CVEs #197

merged 1 commit into from
Dec 27, 2024

Conversation

jbeemster
Copy link
Contributor

Have bumped the required dependencies and have built the binary and image locally after which we now have a clean bill of health:

$ docker scout cves ghcr.io/warpstreamlabs/bento:1.4.0-5-gfc76a5647
    i New version 1.16.1 available (installed version is 1.15.1) at https://github.com/docker/scout-cli
          ✓ SBOM of image already cached, 333 packages indexed
    ✓ No vulnerable package detected


## Overview

                    │                  Analyzed Image
────────────────────┼────────────────────────────────────────────────────
  Target            │  ghcr.io/warpstreamlabs/bento:1.4.0-5-gfc76a5647
    digest          │  29fe5e67d6c1
    platform        │ linux/arm64/v8
    vulnerabilities │    0C     0H     0M     0L
    size            │ 55 MB
    packages        │ 333


## Packages and Vulnerabilities

  No vulnerable packages detected

Copy link
Collaborator

@gregfurman gregfurman left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM! Appreciate the PR 😄 Am currently looking at using govulncheck in our pipelines to alert us of these issues sooner.

@gregfurman gregfurman merged commit cf40d37 into warpstreamlabs:main Dec 27, 2024
3 checks passed
jem-davies pushed a commit that referenced this pull request Jan 4, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants