Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Docker image - vulnerabilities #1640

Open
5 tasks done
Outsidewall opened this issue Jul 15, 2024 · 2 comments
Open
5 tasks done

Docker image - vulnerabilities #1640

Outsidewall opened this issue Jul 15, 2024 · 2 comments
Assignees
Labels
👤 Awaiting Maintainer Response [ISSUE] Response from repo author is pending 🐛 Bug [ISSUE] Ticket describing something that isn't working

Comments

@Outsidewall
Copy link

Environment

Self-Hosted (Docker)

System

Docker (Various)

Version

3.1.1

Describe the problem

I have been running dashy (Docker image) on both Windows and Linux, I have noticed that, there are a number of Critical and Serious vulnerabilities with the image. Scout on Windows lists these very well, on both the latest and Auto tags. Are there any plans to address these?
I love this method of displaying links/apps etc, I'm very concerned of continuing to use it with these vulnerabilities.

Additional info

No response

Please tick the boxes

@Outsidewall Outsidewall added the 🐛 Bug [ISSUE] Ticket describing something that isn't working label Jul 15, 2024
@CrazyWolf13
Copy link
Collaborator

Hi
We take security quite seriously, could you share which vulnerabilites exactly you mean?

The ones displayed by node/npm/yarn ?

I think they have been discussed before but were marked as non-critical for dashy, but we can defenitely take a look.

@Outsidewall
Copy link
Author

Hello,

I use the following system to review the vulnerabilities of docker images, Docker Scout, which is embedded in the Windows Docker Environment, you will see from below that there are a number of vulnerabilities in the latest tag, I have also checked the auto tag which has also many vulnerabilities. Would suggest you run the Windows docker environment yourself have a interactive view of the issues.

image

@liss-bot liss-bot added the 👤 Awaiting Maintainer Response [ISSUE] Response from repo author is pending label Jul 16, 2024
@CrazyWolf13 CrazyWolf13 removed their assignment Sep 1, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
👤 Awaiting Maintainer Response [ISSUE] Response from repo author is pending 🐛 Bug [ISSUE] Ticket describing something that isn't working
Projects
Status: Up Next
Development

No branches or pull requests

4 participants