-
Notifications
You must be signed in to change notification settings - Fork 295
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
fix(security): vulnerabilities found in corda-4-8-all-in-one #2064
Comments
P4 because the Corda AIO images are not meant to be used in production. |
Hi Peter! I'd like to work on this ticket, thank you. |
…perledger-cacti#2064 Signed-off-by: charelle <[email protected]>
…perledger-cacti#2064 Signed-off-by: charelle <[email protected]>
…perledger-cacti#2064 Signed-off-by: charelle <[email protected]>
…perledger-cacti#2064 Signed-off-by: charelle <[email protected]>
…perledger-cacti#2064 Signed-off-by: charelle <[email protected]>
…perledger-cacti#2064 Signed-off-by: charelle <[email protected]>
…perledger-cacti#2064 Signed-off-by: charelle <[email protected]>
…perledger-cacti#2064 Signed-off-by: charelle <[email protected]>
…perledger-cacti#2064 Signed-off-by: charelle <[email protected]>
…perledger-cacti#2064 Signed-off-by: charelle <[email protected]>
…perledger-cacti#2064 Signed-off-by: charelle <[email protected]>
…perledger-cacti#2064 Signed-off-by: charelle <[email protected]>
…perledger-cacti#2064 Signed-off-by: charelle <[email protected]>
…perledger-cacti#2064 Signed-off-by: charelle <[email protected]>
…perledger-cacti#2064 Signed-off-by: charelle <[email protected]>
…perledger-cacti#2064 Signed-off-by: charelle <[email protected]>
…perledger-cacti#2064 Signed-off-by: charelle <[email protected]>
…perledger-cacti#2064 Signed-off-by: charelle <[email protected]>
…perledger-cacti#2064 Signed-off-by: charelle <[email protected]>
…perledger-cacti#2064 Signed-off-by: charelle <[email protected]>
…perledger-cacti#2064 Signed-off-by: charelle <[email protected]>
Hello @jagpreetsinghsasan I am also currently helping on this one. |
This PR/issue depends on: |
Fixes hyperledger-cacti#2064 Signed-off-by: adrianbatuto <[email protected]>
Fixes hyperledger-cacti#2064 Signed-off-by: adrianbatuto <[email protected]>
Fixes hyperledger-cacti#2064 Signed-off-by: adrianbatuto <[email protected]>
Fixes hyperledger-cacti#2064 Signed-off-by: adrianbatuto <[email protected]>
Fixes hyperledger-cacti#2064 Signed-off-by: adrianbatuto <[email protected]>
Fixes hyperledger-cacti#2064 Signed-off-by: adrianbatuto <[email protected]>
Fixes hyperledger-cacti#2064 Signed-off-by: adrianbatuto <[email protected]>
Fixes hyperledger-cacti#2064 Signed-off-by: adrianbatuto <[email protected]>
Fixes hyperledger-cacti#2064 Signed-off-by: adrianbatuto <[email protected]>
The vulnerability issues found on the Trivy scan had to do with the Corda jar files. I'll raise a ticket to corda giving them the list of vulnerabilities we have found so they can fix it. Will update this ticket with the issue ticket raised to corda once I have it. |
@adrianbatuto Could you please make the issue title unique (CVE ID or IDs of the most severe vulnerabilities is my go-to in these cases - while keeping in mind the maximum length for the commit linter at the same time) |
We've retired the corda v4.8 AIO image. Also, we'll pause fixes of CVEs in test tools as they are not getting deployed into production. |
List of vulnerabilities found in corda-4-8-all-in-one image during Azure Container scan.
Depends on #2621
The text was updated successfully, but these errors were encountered: