Skip to content

General dependency vulnerabilities #2300

@pavel-ch

Description

@pavel-ch

As I am involved in our CyberSecurity programm, I checked at first stage Phoebus dependencies for known vulnerabilities. I am sure we have to solve these issues, it will be sooner or later necessary anyway.
The scan protocol of the OWASP dependency-check tool is attached. Please note that beside a number of HIGH severity dependencies, we have also several CRITICAL severity ones.
I know limitations of these SCM scans. Effective vulnerabilities are always dependent on HOW these components are used. But, anyway, I am convinced we should make some effort to minimize alerts, by for example upgrading dependencies to last versions without known vulnerabilities.
For the future, it is perhaps necessary to establish a project wide policy handling this issue.
Thank you for comments.
Dependency-Check Report.pdf

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions