xgo
xgo copied to clipboard
hundreds of vulnerabilities reported in images
Docker Scout identifies hundreds of CVE's in the xgo images, including critical severity vulnerabilities.
docker-scout-vulnerability-report.txt
What if we published xgo atop Fedora (41), which often acts as a more secure base image than Debian/Ubuntu family?
The reported cves from your report are all go cves, not ones based on the os. It seems like the go version it reported (1.17) is either wrongly detected or the docker image is out of date.