xeol-io / xeol

A scanner for end-of-life (EOL) software and dependencies in container images, filesystems, and SBOMs
https://www.xeol.io/
Apache License 2.0
348 stars 21 forks source link

Xeol image itself EOL #422

Closed m-barthelemy closed 3 weeks ago

m-barthelemy commented 3 weeks ago

What happened: Xeol detects its own Docker image as EOL

What you expected to happen: Xeol uses up to date base image and packages

How to reproduce it (as minimally and precisely as possible):

Anything else we need to know?: The noqcks/xeol:v0.10.0 image is running on a quite old and now EOL version of Alpine. So Xeol now detects itself as being end of life :)

Additionally, the image seems to use a version of Golang affected by CVE-2024-24790 and others.

Environment: