Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

vulnerabilities found in accurics/terrascan_atlantis image #1029

Closed
mkhodave opened this issue Sep 23, 2021 · 0 comments · Fixed by #1054
Closed

vulnerabilities found in accurics/terrascan_atlantis image #1029

mkhodave opened this issue Sep 23, 2021 · 0 comments · Fixed by #1054

Comments

@mkhodave
Copy link

  • accurics/terrascan_atlantis image: 1.10.0

Description

We will be planning to use accurics/terrascan_atlantis image tag 1.10.0 but found multiple vulnerabilities with severity critical & high

What I Did

$ trivy accurics/terrascan_atlantis
2021-09-23T12:36:03.549+0530	INFO	Need to update DB
2021-09-23T12:36:03.549+0530	INFO	Downloading DB...
24.03 MiB / 24.03 MiB [---------------------------------------------------------------------------------------------] 100.00% 6.12 MiB p/s 4s
2021-09-23T12:36:17.661+0530	INFO	Detected OS: alpine
2021-09-23T12:36:17.661+0530	INFO	Detecting Alpine vulnerabilities...
2021-09-23T12:36:17.662+0530	INFO	Number of PL dependency files: 3
2021-09-23T12:36:17.662+0530	INFO	Detecting gobinary vulnerabilities...
2021-09-23T12:36:17.662+0530	WARN	constraint error (v3.2.0+incompatible): improper constraint: 

accurics/terrascan_atlantis (alpine 3.12.0)
===========================================
Total: 70 (UNKNOWN: 0, LOW: 10, MEDIUM: 27, HIGH: 30, CRITICAL: 3)

I think this should be fixed by updating base alpine image tag to alpine:3.14.2

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging a pull request may close this issue.

1 participant