spotify / lighthouse-audit-service

Apache License 2.0
96 stars 30 forks source link

Lot's of vulnerabilities for image v1.0.2 #65

Closed jvilimek closed 2 years ago

jvilimek commented 3 years ago

Dears,

we have just executed vulnerability scan over the lastest (v1.0.2) lighthouse-audit-service and there are lot's of vulnerabilities there: image

I believe lot's of them are caused by using node:12 base image.

Could you please try to do the hardening of the image so it is not a threat to use it in our/other environments? E.g. see https://snyk.io/blog/10-best-practices-to-containerize-nodejs-web-applications-with-docker/

or what do you suggest?

jvilimek commented 3 years ago

@ODEit WDYT?

jvilimek commented 3 years ago

@kaimallea ?

jvilimek commented 3 years ago

@erikxiv ?

kaimallea commented 3 years ago

@jvilimek Hey Jan, thanks for raising this issue. We're tracking this internally and will update soon!

kaimallea commented 2 years ago

:tada: This issue has been resolved in version 2.0.0 :tada:

The release is available on:

Your semantic-release bot :package::rocket: