eclipse-tractusx / sldt-semantic-hub

Apache License 2.0
6 stars 10 forks source link

High finding in Trivy scan- check base image #210

Closed RazvanZmau closed 6 months ago

RazvanZmau commented 7 months ago

Check if base image (eclipse-temurin:17-jre-alpine) has been updated.

Currently we have two high findings in openssl (CVE-2023-5678, CVE-2023-5363) which is part of the base image but can't be fixed due some legal restrictions.

If base image is available in newer version, this high findings maybe will be fixed.

JIRA ticket #1500