TerriaJS / terriajs

A library for building rich, web-based geospatial data platforms.
https://terria.io
Apache License 2.0
1.19k stars 364 forks source link

Noisy security reports from Trivy #6790

Open pjonsson opened 1 year ago

pjonsson commented 1 year ago

Edit: updated image+text for TerriaMap 0.2.1 release (+yarn upgrade)

I'm not sure which project to file this issue on, so my apologies if it's in the wrong place.

Trivy reports a reasonable amount of security issues in TerriaMap, but I believe at least some of them are caused by terriajs.

It would be lovely if some of the dependencies could be updated to reduce the noise from Trivy and other scanners. Attaching a screenshot of the critical/high vulnerabilities when scanning a TerriaMap-image.

image

pjonsson commented 2 months ago

Is there something we can do to help with this?