DataDog / datadog-lambda-extension

Datadog Lambda Extension
Apache License 2.0
81 stars 5 forks source link

CVEs in DD Lambda Extension Layer #409

Open luneo7 opened 1 month ago

luneo7 commented 1 month ago

Our CVE analysis tools is throwing a bunch of warnings for CVEs coming from the DD Lambda Extension Layer: Image

Can you guys update the dependencies to handle those?

purple4reina commented 1 month ago

Hi @luneo7, thanks for reaching out. We currently have a github action set up to run nightly to check for vulnerabilities using a variety of tools, yet we haven't seen any of these show up on the current version of the extension.

In order to investigate, can you please share with us which CVE analysis tool you are using, how you're calling it, and the version of the extension you are analysing? The most recent version of the extension is v65.