<#140 Vulnerabilities in base-image alpine3.17> Is...
# pact-broker
g
#140 Vulnerabilities in base-image alpine3.17 Issue created by navalPorsche2023 Pre issue-raising checklist I have already (please mark the applicable with an
x
): • [x ] Confirmed this is the right place to raise the issue - only issues related to the Dockerization of the Pact Broker should be raised here. Issues related to the Pact Broker application itself should be raised in the Pact Broker project. • [ x] Upgraded to the latest Pact Broker Docker image OR • [ x] Checked the </CHANGELOG.md|CHANGELOG> to see if the issue I am about to raise has been fixed • [x ] Read the Troubleshooting page Software versions • pact-broker gem version: eg 2.3.1 • pact-broker docker version: eg 2.3.1-1 • OS: e.g. Mac OSX 10.11.5 • pact broker client details: eg. pact-ruby-standalone CLI v 1.23.0 Expected behaviour No high vulnerabilities in the latest image pactfoundation/pact-broker:latest Actual behaviour We have these two high vulnerabilities: • ncurses6.3 p20221119 r0 CVE-2023-29491 • openssl3.0.8 r4 CVE-2023-2650 Steps to reproduce Run the image through clair (AWS image scan) or alternatives scans: trivy or anchor Relevent log files xxx pact-foundation/pact-broker-docker