Skip to content

Deal with vulnerabilities shown in Dockerhub #14889

Open
@carminevassallo

Description

@carminevassallo

Dear team,

we noticed the presence of several high-severity vulnerabilities raised on our official SonarQube image tags. We have internal processes and tools to assess and review possible vulnerabilities and we would like to know how to best align all these internal processes with what is shown in Dockerhub asap. Two initial questions:

  • how can we deal with the vulnerabilities raised on Dockerhub and justify/mark them as harmless alerts?
  • is it a possibility to disable the scan and link to our tooling if people are interested in knowing more about any true vulnerabilities for SonarQube?

I hope this is the right channel to discuss this :)

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions