higlass / higlass-docker

Builds a docker container wrapping higlass-server and higlass-client in nginx
MIT License
32 stars 14 forks source link

security (CVEs) issues - 4 critical and 11 high - most fixed by upgrading components #183

Open brianrepko opened 2 years ago

brianrepko commented 2 years ago

higlass-docker-scan.html.txt

You can find the attached Aqua Scan report - remove the .txt outer extension and open in a browser. Under Vulnerabilities you can see multiple Critical and High issues related to out of date packages / libraries. Other issues are based on this being an Ubuntu image (I think you can find alpine base images that are secure).

Critical look to be Django (fix 2.2.26 --> 2.2.28), Werkzeug (2.0.3 --> 2.2.1) , and joblib (1.1.0 --> 1.2.0) High are a mix of Ubuntu issues and some are pypi or javascript components (mistune) Happy to re-scan for you.