-
# Description of the problem
I noticed that .tiff and .pdf files do not create image thumbnails that show the image when you attach them to experiment. Also, you cannot add .tiff or .pdf as an inline…
-
We should stop relying on osvdb and cve ids as canonical identifiers as they may not be always present, as in the case where we get a vuln before it's in either db.
- [ ] Add a new field to the schem…
-
We recently had a question from our security team regarding CVE-2016-3610, and on how and why we used "less than" in the criterion instead of "equal to".
As per NVD and Oracle, only Java 8u9…
-
Many Docker projects are now using Alpine as base for their containers ([Deis](https://github.com/deis/deis) for example). Just last month the Alpine repo had ![Docker Pulls](https://img.shields.io/d…
-
http://codevigilant.com/disclosures/
-
Some stories may contain sensitive content, such as those tracking work on CVE.
In such case, we might not want to ease discoverability of these stories into well indexed GH issue mirrors, because …
-
Here is a report from the oss-security mailing list for [Vulnerability Roundup 27](https://github.com/NixOS/nixpkgs/issues/24319).
[Skip to First Email](#first-email)
# Instructions:
## Identificati…
-
Hi there,
With the recent security updates for the Node.js image on my mind (https://github.com/docker-library/official-images/pull/1239) I wanted to open up a discussion to see if there are ways to …
-
#### Error on `make`
```
ec_ameth.c:70:29: error: unknown type name 'CMS_RecipientInfo'
static int ecdh_cms_decrypt(CMS_RecipientInfo *ri);
^
ec_ameth.c:71:29: error: unkn…
-
Regarding: https://gist.github.com/frohoff/24af7913611f8406eaf3
Since you coordinated with Oracle and it is fixed in a fairly old version, can you ask what CVE ID that issue tracks to and update the …