tektoncd / catalog

Catalog of shared Tasks and Pipelines.
Apache License 2.0
660 stars 575 forks source link

Patch vulnerabilities and exposures for the Verified Catalogs #1112

Open QuanZhang-William opened 1 year ago

QuanZhang-William commented 1 year ago

In TEP-0115, we selected 5 resources to be supported at Verified support tier, where the @tektoncd/catalog-maintainers are expected to patch the detected CVEs.

In TEP-0079, we have proposed to use the Artifact Hub Scanner service (which uses Trivy) to generate vulnerability reports and displayed on the Artifact Hub.

Here is the list of resources (and the underlying images) that will be serviced at Verified tier:

The security reports for the above resources currently contains a bunch of CVEs, which should be addressed before we can claim these are the Verified Catalogs.

We can create separate issues to track the progress for each resource.

Steps to Reproduce the Problem

The Artifact Hub uses Trivy to scan the container images, you can get the same security report by running Trivy locally:

  1. Install Trivy
  2. run trivy image [container image name]

@tektoncd/catalog-maintainers

tekton-robot commented 1 year ago

Issues go stale after 90d of inactivity. Mark the issue as fresh with /remove-lifecycle stale with a justification. Stale issues rot after an additional 30d of inactivity and eventually close. If this issue is safe to close now please do so with /close with a justification. If this issue should be exempted, mark the issue as frozen with /lifecycle frozen with a justification.

/lifecycle stale

Send feedback to tektoncd/plumbing.

vinamra28 commented 1 year ago

/remove-lifecycle stale /lifecycle frozen this we might revisit in future