goodwithtech / dockle

Container Image Linter for Security, Helping build the Best-Practice Docker Image, Easy to start
https://containers.goodwith.tech/
Apache License 2.0
2.8k stars 139 forks source link

CVE Need to be fixed #185

Open stefyvarghese opened 2 years ago

stefyvarghese commented 2 years ago

Some packages version must be upgraded within the code to fix the High Vulnerability Alerts We are using action goodwithtech/dockle, and on scanning these Alerts on High Priority. We would Request that these necessary changes are done.

Please find the Attached screenshots.

image

image

tomoyamachi commented 2 years ago
We need to change the following dependency packages: https://github.com/goodwithtech/deckoder/blob/7ee08170ffbf793be0e6645d8a328b1928841fef/go.sum#L213-L215 https://github.com/containers/image/blob/2bb3f3e44c5cbe532a3cdbe735f78c21418f8dc2/go.sum#L287-L288