dynatrace-oss / dynatrace-gcp-monitor

Dynatrace integration for Google Cloud Platform monitoring
https://www.dynatrace.com/support/help/technology-support/cloud-platforms/google-cloud-platform/
Apache License 2.0
35 stars 20 forks source link

Vulnerabilities to be addressed #390

Closed peijunzh closed 1 year ago

peijunzh commented 1 year ago

With aqua/scanner:2022.4.217 to scan image dynatrace/dynatrace-gcp-monitor:release-1.1.0, there are two high issues found. Can those issues be fixed please?

image
joaquinfilipic-dynatrace commented 1 year ago

The cryptography version has been bumped up already, next release will have it updated. It uses internally openssl, as I far as I know, so that scanned vulnerability should be linked (our explicit use of openssl is in scripts, outside the source code).