Open
Description
Dear team,
we noticed the presence of several high-severity vulnerabilities raised on our official SonarQube image tags. We have internal processes and tools to assess and review possible vulnerabilities and we would like to know how to best align all these internal processes with what is shown in Dockerhub asap. Two initial questions:
- how can we deal with the vulnerabilities raised on Dockerhub and justify/mark them as harmless alerts?
- is it a possibility to disable the scan and link to our tooling if people are interested in knowing more about any true vulnerabilities for SonarQube?
I hope this is the right channel to discuss this :)
Metadata
Metadata
Assignees
Labels
No labels