Skip to content

CVEs reported against dependencytrack/apiserver #4479

Closed Answered by valentijnscholten
lokesh2019 asked this question in Q&A
Discussion options

You must be logged in to vote

The easiest solution is to update the Dockerfile to use the latest Alpine base image and build the containers yourself.
The build process is here: https://github.com/DependencyTrack/dependency-track/blob/master/.github/workflows/_meta-build.yaml

Even easier might be to look at the vulnerabilities and conclude they are not a high risk :-)

Replies: 1 comment

Comment options

You must be logged in to vote
0 replies
Answer selected by lokesh2019
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants