You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Dependency-Track contains some vulnerabilities caused by Alpine 2.2.5:
How should this be handled without updating to Alpine 2.2.6 (not available) or 3.0.0-Snaphot?
Steps to Reproduce
Scan Dependency-Track source with Dependency-Track
Expected Behavior
Regular and shorter update interval for dependencies.
We don't usually publish new releases to resolve vulnerable dependencies, unless the vulnerabilities are exploitable and have demonstratable impact. In this case, none of the vulnerabilities are exploitable. If you have contrary evidence, please let us know and we'll act accordingly.
The majority of these findings will be resolved in Dependency-Track v4.12.0. In particular the Jetty upgrade required a bit of refactoring (see #3730), so it is not feasible to include it in a bugfix release.
Current Behavior
Dependency-Track contains some vulnerabilities caused by Alpine 2.2.5:
How should this be handled without updating to Alpine 2.2.6 (not available) or 3.0.0-Snaphot?
Steps to Reproduce
Expected Behavior
Regular and shorter update interval for dependencies.
Dependency-Track Version
4.11.2
Dependency-Track Distribution
Executable WAR
Database Server
Microsoft SQL Server
Database Server Version
No response
Browser
Microsoft Edge
Checklist
The text was updated successfully, but these errors were encountered: