-
Notifications
You must be signed in to change notification settings - Fork 1.2k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Unapproved vulnerabilitie CVE-2020-28928 #819
Comments
See https://github.com/docker-library/faq#why-does-my-security-scanner-show-that-an-image-has-cves A CVE doesn't imply having an actual vulnerability, and often is even a false positive (given how most distributions handle versioning/security updates in stable releases). If there are actionable items we can resolve, we're happy to do so (and do so actively). We update all Debian based images to include any updates in apt packages at least monthly (we regenerate the base images and then rebuild all dependent images). |
Thank you for your quick response. |
listing installed musl package version
You can check the postgres:13-alpine - musl-1.2.2-r0 - OK
postgres:13.1-alpine - musl-1.2.2-r0 - OK
postgres:13.0-alpine - musl-1.1.24-r9 - OLD ( last pushed 4 months ago by ! )
|
Thanks a lot for the explanation. |
checking with a fresh clair-db - it is still reporting for
|
This issue can be considered resolved. |
Hello.
I noticed that the Clair scanner reports about the unapproved vulnerability for all 13 Postgres alpine-based docker images.
The issue with the "musl" package.
All details can be reviewed by the following link:
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-28928
Could you please fix this issue?
Thanks.
The text was updated successfully, but these errors were encountered: