Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

🔴 | Parent Docker Image CVE Risk (max): [High] #522

Open
wants to merge 1 commit into
base: main
Choose a base branch
from
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion Dockerfile
Original file line number Diff line number Diff line change
@@ -1 +1 @@
FROM bash:alpine3.16
FROM bash:alpine3.16@sha256:06fca7ba6a55c2eda6013fd1ab428c2e15f0d17150f433c78fcb8a0e416157a0
385 changes: 385 additions & 0 deletions provenance/bash-alpine3.16-sbom.json
Original file line number Diff line number Diff line change
@@ -0,0 +1,385 @@
{
"$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
"version": 1,
"metadata": {
"tools": [
{
"name": "trivy",
"vendor": "aquasecurity",
"version": "unknown"
}
],
"component": {
"name": "bash",
"purl": "pkg:oci/bash@alpine3.16?digest=sha256:06fca7ba6a55c2eda6013fd1ab428c2e15f0d17150f433c78fcb8a0e416157a0",
"type": "library",
"bom-ref": "pkg:oci/bash@alpine3.16?digest=sha256:06fca7ba6a55c2eda6013fd1ab428c2e15f0d17150f433c78fcb8a0e416157a0",
"version": "alpine3.16"
},
"timestamp": "2024-12-08T19:25:37.945450+00:00"
},
"bomFormat": "CycloneDX",
"components": [
{
"name": ".bash-rundeps",
"type": "library",
"bom-ref": "BomRef.19054486706129836.42805505402835553",
"version": "20230329.182230"
},
{
"name": "alpine",
"type": "library",
"bom-ref": "BomRef.4408575363986077.42665571596519913",
"version": "3.16.5"
},
{
"name": "alpine-baselayout",
"type": "library",
"bom-ref": "BomRef.877288849128266.48973099852721313",
"version": "3.2.0-r23"
},
{
"name": "alpine-baselayout-data",
"type": "library",
"bom-ref": "BomRef.6962011325398544.5728819779406347",
"version": "3.2.0-r23"
},
{
"name": "alpine-keys",
"type": "library",
"bom-ref": "BomRef.08904074307871068.7290300134550762",
"version": "2.4-r1"
},
{
"name": "apk-tools",
"type": "library",
"bom-ref": "BomRef.8267579387852254.9391979205563733",
"version": "2.12.9-r3"
},
{
"name": "busybox",
"type": "library",
"bom-ref": "BomRef.7635211301340971.5610048649255968",
"version": "1.35.0-r17"
},
{
"name": "ca-certificates-bundle",
"type": "library",
"bom-ref": "BomRef.2980265042666189.240614682668577",
"version": "20220614-r0"
},
{
"name": "e62ec2d4-9daa-49fd-a04b-281f40d8ca69",
"type": "library",
"bom-ref": "BomRef.5920959258346439.04706489137344183",
"version": "unknown"
},
{
"name": "libc-utils",
"type": "library",
"bom-ref": "BomRef.6813142525114865.649692196868289",
"version": "0.7.2-r3"
},
{
"name": "libcrypto1.1",
"type": "library",
"bom-ref": "BomRef.9087024368381166.30920466237009026",
"version": "1.1.1t-r2"
},
{
"name": "libssl1.1",
"type": "library",
"bom-ref": "BomRef.3848514833324991.3396178639092091",
"version": "1.1.1t-r2"
},
{
"name": "musl",
"type": "library",
"bom-ref": "BomRef.873181307293822.5163617576312663",
"version": "1.2.3-r2"
},
{
"name": "musl-utils",
"type": "library",
"bom-ref": "BomRef.900329402619571.9136863197710786",
"version": "1.2.3-r2"
},
{
"name": "ncurses-libs",
"type": "library",
"bom-ref": "BomRef.3528826455440204.6533662522387004",
"version": "6.3_p20220521-r0"
},
{
"name": "ncurses-terminfo-base",
"type": "library",
"bom-ref": "BomRef.3260409991003447.4342424274699027",
"version": "6.3_p20220521-r0"
},
{
"name": "pkg:apk/alpine/.bash-rundeps@20230329.182230?arch=noarch&distro=3.16.5",
"type": "library",
"bom-ref": "BomRef.5256457349931817.1169719913422742",
"version": "unknown"
},
{
"name": "pkg:apk/alpine/alpine-baselayout-data@3.2.0-r23?arch=x86_64&distro=3.16.5",
"type": "library",
"bom-ref": "BomRef.7716587530896214.14999317857866445",
"version": "unknown"
},
{
"name": "pkg:apk/alpine/alpine-baselayout@3.2.0-r23?arch=x86_64&distro=3.16.5",
"type": "library",
"bom-ref": "BomRef.38431530828298255.008307897916004614",
"version": "unknown"
},
{
"name": "pkg:apk/alpine/alpine-keys@2.4-r1?arch=x86_64&distro=3.16.5",
"type": "library",
"bom-ref": "BomRef.7472847435399421.1442028960033186",
"version": "unknown"
},
{
"name": "pkg:apk/alpine/apk-tools@2.12.9-r3?arch=x86_64&distro=3.16.5",
"type": "library",
"bom-ref": "BomRef.0915943483392142.6592882633050656",
"version": "unknown"
},
{
"name": "pkg:apk/alpine/busybox@1.35.0-r17?arch=x86_64&distro=3.16.5",
"type": "library",
"bom-ref": "BomRef.6425834192225766.44272494627791537",
"version": "unknown"
},
{
"name": "pkg:apk/alpine/ca-certificates-bundle@20220614-r0?arch=x86_64&distro=3.16.5",
"type": "library",
"bom-ref": "BomRef.456517468754684.5895302426709506",
"version": "unknown"
},
{
"name": "pkg:apk/alpine/libc-utils@0.7.2-r3?arch=x86_64&distro=3.16.5",
"type": "library",
"bom-ref": "BomRef.8103107133852415.6097708514288536",
"version": "unknown"
},
{
"name": "pkg:apk/alpine/libcrypto1.1@1.1.1t-r2?arch=x86_64&distro=3.16.5",
"type": "library",
"bom-ref": "BomRef.4606068494401412.03423828095433423",
"version": "unknown"
},
{
"name": "pkg:apk/alpine/libssl1.1@1.1.1t-r2?arch=x86_64&distro=3.16.5",
"type": "library",
"bom-ref": "BomRef.4090585595062116.31495906768633763",
"version": "unknown"
},
{
"name": "pkg:apk/alpine/musl-utils@1.2.3-r2?arch=x86_64&distro=3.16.5",
"type": "library",
"bom-ref": "BomRef.008160723592450458.4954256050485458",
"version": "unknown"
},
{
"name": "pkg:apk/alpine/musl@1.2.3-r2?arch=x86_64&distro=3.16.5",
"type": "library",
"bom-ref": "BomRef.25002791652591794.5611259015680109",
"version": "unknown"
},
{
"name": "pkg:apk/alpine/ncurses-libs@6.3_p20220521-r0?arch=x86_64&distro=3.16.5",
"type": "library",
"bom-ref": "BomRef.8108092836003269.7686414522999572",
"version": "unknown"
},
{
"name": "pkg:apk/alpine/ncurses-terminfo-base@6.3_p20220521-r0?arch=x86_64&distro=3.16.5",
"type": "library",
"bom-ref": "BomRef.288412428073325.3634057150855481",
"version": "unknown"
},
{
"name": "pkg:apk/alpine/scanelf@1.3.4-r0?arch=x86_64&distro=3.16.5",
"type": "library",
"bom-ref": "BomRef.6515106887264556.8108643472617869",
"version": "unknown"
},
{
"name": "pkg:apk/alpine/ssl_client@1.35.0-r17?arch=x86_64&distro=3.16.5",
"type": "library",
"bom-ref": "BomRef.03328439754412915.5739854729480603",
"version": "unknown"
},
{
"name": "pkg:apk/alpine/zlib@1.2.12-r3?arch=x86_64&distro=3.16.5",
"type": "library",
"bom-ref": "BomRef.7040064644728308.4991282054375993",
"version": "unknown"
},
{
"name": "pkg:oci/bash@sha256%3A06fca7ba6a55c2eda6013fd1ab428c2e15f0d17150f433c78fcb8a0e416157a0?arch=amd64&repository_url=index.docker.io%2Flibrary%2Fbash",
"type": "library",
"bom-ref": "BomRef.8691080551171723.209793878061879",
"version": "unknown"
},
{
"name": "scanelf",
"type": "library",
"bom-ref": "BomRef.37185144307051443.11185894703434596",
"version": "1.3.4-r0"
},
{
"name": "ssl_client",
"type": "library",
"bom-ref": "BomRef.7444314266258425.543142685785477",
"version": "1.35.0-r17"
},
{
"name": "zlib",
"type": "library",
"bom-ref": "BomRef.23763629071508885.9345719906277112",
"version": "1.2.12-r3"
}
],
"specVersion": "1.6",
"dependencies": [
{
"ref": "BomRef.5920959258346439.04706489137344183"
},
{
"ref": "BomRef.5256457349931817.1169719913422742"
},
{
"ref": "BomRef.7716587530896214.14999317857866445"
},
{
"ref": "BomRef.38431530828298255.008307897916004614"
},
{
"ref": "BomRef.7472847435399421.1442028960033186"
},
{
"ref": "BomRef.0915943483392142.6592882633050656"
},
{
"ref": "BomRef.6425834192225766.44272494627791537"
},
{
"ref": "BomRef.456517468754684.5895302426709506"
},
{
"ref": "BomRef.8103107133852415.6097708514288536"
},
{
"ref": "BomRef.4606068494401412.03423828095433423"
},
{
"ref": "BomRef.4090585595062116.31495906768633763"
},
{
"ref": "BomRef.008160723592450458.4954256050485458"
},
{
"ref": "BomRef.25002791652591794.5611259015680109"
},
{
"ref": "BomRef.8108092836003269.7686414522999572"
},
{
"ref": "BomRef.288412428073325.3634057150855481"
},
{
"ref": "BomRef.6515106887264556.8108643472617869"
},
{
"ref": "BomRef.03328439754412915.5739854729480603"
},
{
"ref": "BomRef.7040064644728308.4991282054375993"
},
{
"ref": "BomRef.8691080551171723.209793878061879"
},
{
"ref": "BomRef.19054486706129836.42805505402835553"
},
{
"ref": "BomRef.4408575363986077.42665571596519913"
},
{
"ref": "BomRef.877288849128266.48973099852721313"
},
{
"ref": "BomRef.6962011325398544.5728819779406347"
},
{
"ref": "BomRef.08904074307871068.7290300134550762"
},
{
"ref": "BomRef.8267579387852254.9391979205563733"
},
{
"ref": "BomRef.7635211301340971.5610048649255968"
},
{
"ref": "BomRef.2980265042666189.240614682668577"
},
{
"ref": "BomRef.6813142525114865.649692196868289"
},
{
"ref": "BomRef.9087024368381166.30920466237009026"
},
{
"ref": "BomRef.3848514833324991.3396178639092091"
},
{
"ref": "BomRef.873181307293822.5163617576312663"
},
{
"ref": "BomRef.900329402619571.9136863197710786"
},
{
"ref": "BomRef.3528826455440204.6533662522387004"
},
{
"ref": "BomRef.3260409991003447.4342424274699027"
},
{
"ref": "BomRef.37185144307051443.11185894703434596"
},
{
"ref": "BomRef.7444314266258425.543142685785477"
},
{
"ref": "BomRef.23763629071508885.9345719906277112"
},
{
"ref": "pkg:oci/bash@alpine3.16?digest=sha256:06fca7ba6a55c2eda6013fd1ab428c2e15f0d17150f433c78fcb8a0e416157a0",
"dependsOn": [
"BomRef.6515106887264556.8108643472617869",
"BomRef.38431530828298255.008307897916004614",
"BomRef.8691080551171723.209793878061879",
"BomRef.7716587530896214.14999317857866445",
"BomRef.456517468754684.5895302426709506",
"BomRef.7040064644728308.4991282054375993",
"BomRef.0915943483392142.6592882633050656",
"BomRef.288412428073325.3634057150855481",
"BomRef.5256457349931817.1169719913422742",
"BomRef.25002791652591794.5611259015680109",
"BomRef.6425834192225766.44272494627791537",
"BomRef.4606068494401412.03423828095433423",
"BomRef.8108092836003269.7686414522999572",
"BomRef.4090585595062116.31495906768633763",
"BomRef.03328439754412915.5739854729480603",
"BomRef.5920959258346439.04706489137344183",
"BomRef.7472847435399421.1442028960033186",
"BomRef.8103107133852415.6097708514288536",
"BomRef.008160723592450458.4954256050485458"
]
}
],
"serialNumber": "urn:uuid:a13459a6-6c58-451e-ae34-0f1c66fad3cc"
}