GitHub
02/09/2023, 6:19 AMx):
☑︎ Upgraded to the latest Pact Broker OR
☑︎ Checked the CHANGELOG to see if the issue I am about to raise has been fixed
☐ Created an executable example that demonstrates the issue using either a:
• Dockerfile
• Git repository with a Travis or Appveyor (or similar) build
Software versions
• pact-broker docker version: eg latest
• OS: e.g. Mac OSX 13.1
Expected behaviour
Docker image with no security vulnerabilities
Actual behaviour
Docker image which contains security vulnerabilities (including high and medium)
Steps to reproduce
1. Install a tool named [trivy](<https://github.com/aquasecurity/trivy>) which is used to scan docker images for security vulnerabilities.
2. Scan the pact broker image for vulnerabilities with the below command
trivy image pactfoundation/pact-broker:latest
3. This will give the vulnerabilities
Scan Result | Security Vulnerabilities
image▾
image▾
image▾