higlass-docker icon indicating copy to clipboard operation
higlass-docker copied to clipboard

security (CVEs) issues - 4 critical and 11 high - most fixed by upgrading components

Open brianrepko opened this issue 1 year ago • 0 comments

higlass-docker-scan.html.txt

You can find the attached Aqua Scan report - remove the .txt outer extension and open in a browser. Under Vulnerabilities you can see multiple Critical and High issues related to out of date packages / libraries. Other issues are based on this being an Ubuntu image (I think you can find alpine base images that are secure).

Critical look to be Django (fix 2.2.26 --> 2.2.28), Werkzeug (2.0.3 --> 2.2.1) , and joblib (1.1.0 --> 1.2.0) High are a mix of Ubuntu issues and some are pypi or javascript components (mistune) Happy to re-scan for you.

brianrepko avatar Nov 09 '22 18:11 brianrepko