owasp-noir / noir

Attack surface detector that identifies endpoints by static analysis
https://owasp.org/www-project-noir/
MIT License
554 stars 41 forks source link

noir contains outdated Ubuntu packages #380

Closed hahwul closed 1 month ago

hahwul commented 1 month ago

A scan of this snap shows that it was built with packages from the Ubuntu archive that have since received security updates. The following lists new USNs for affected binary packages in each snap revision:

Revision r6 (amd64; channels: stable, candidate, beta, edge)

Simply rebuilding the snap will pull in the new security updates and resolve this. If your snap also contains vendored code, now might be a good time to review it for any needed updates.

Thank you for your snap and for attending to this matter.

References:


from canonical

hahwul commented 1 month ago

We don't have a vendor code. I think we can just update it. (v0.17.0)