Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

umitools Vulnerability Analysis #136

Open
github-actions bot opened this issue Oct 29, 2024 · 0 comments
Open

umitools Vulnerability Analysis #136

github-actions bot opened this issue Oct 29, 2024 · 0 comments

Comments

@github-actions
Copy link

Significant issues present in bwa, see quickview and recommendations below, but run CVE analysis locally.



  Target             │  getwilds/umitools:latest  │    0C     2H     3M   115L     4?   
    digest           │  33e6608f03f1              │                                     
  Base image         │  python:3.12               │    0C     2H     3M   115L     4?   
  Updated base image │  python:3.12-slim          │    0C     0H     0M    28L          
                     │                            │           -2     -3    -87     -4   

What's next:
    View vulnerabilities → docker scout cves getwilds/umitools:latest
    View base image update recommendations → docker scout recommendations getwilds/umitools:latest
    Include policy results in your quickview by supplying an organization → docker scout quickview getwilds/umitools:latest --org <organization>



  Target   │  getwilds/umitools:latest   
    digest │  33e6608f03f1               

## Recommended fixes

  Base image is  python:3.12 

  Name            │  3.12                                                                      
  Digest          │  sha256:1b7f52f4a473d9d112ce255705e4d3c421d66b02d034f4b1ccb6d36acf33edaf   
  Vulnerabilities │    0C     2H     3M   115L     4?                                          
  Pushed          │ 1 week ago                                                                 
  Size            │ 381 MB                                                                     
  Packages        │ 575                                                                        
  Flavor          │ debian                                                                     
  OS              │ 12                                                                         
  Runtime         │ 3.12.7                                                                     

                                                                    
  │ The base image is also available under the supported tag(s)     
  `3.12-                                                            
  │ bookworm`, `3.12.7`, `3.12.7-bookworm`. If you want to display   
  │ recommendations specifically for a different tag, please re-run  
  │ the command using the `--tag` flag.                              



Refresh base image
  Rebuild the image using a newer base image version. Updating this may result in breaking changes.

  ✓ This image version is up to date.


Change base image
  The list displays new recommended tags in descending order, where the top results are rated as most suitable.


              Tag              │                         Details                         │   Pushed   │          Vulnerabilities            
───────────────────────────────┼─────────────────────────────────────────────────────────┼────────────┼─────────────────────────────────────
   3.12-slim                   │ Benefits:                                               │ 1 week ago │    0C     0H     0M    28L          
  Patch runtime version update │ • Patch runtime version update                          │            │           -2     -3    -87     -4   
  Also known as:               │ • Image is smaller by 319 MB                            │            │                                     
  • 3.12.7-slim                │ • Image contains 419 fewer packages                     │            │                                     
  • 3.12.7-slim-bookworm       │ • Image introduces no new vulnerability but removes 92  │            │                                     
  • 3.12-slim-bookworm         │ • Tag is using slim variant                             │            │                                     
                               │                                                         │            │                                     
                               │ Image details:                                          │            │                                     
                               │ • Size: 46 MB                                           │            │                                     
                               │ • Flavor: debian                                        │            │                                     
                               │ • OS: 12                                                │            │                                     
                               │ • Runtime: 3.12.7                                       │            │                                     
                               │ • Slim: ✓                                               │            │                                     
                               │                                                         │            │                                     
                               │                                                         │            │                                     
                               │                                                         │            │                                     
   alpine                      │ Benefits:                                               │ 1 week ago │    0C     0H     0M     0L     1?   
  Tag is preferred tag         │ • Minor runtime version update                          │            │           -2     -3   -115     -3   
  Also known as:               │ • Image is smaller by 348 MB                            │            │                                     
  • alpine3.20                 │ • Image contains 534 fewer packages                     │            │                                     
  • 3.13.0-alpine              │ • Tag is preferred tag                                  │            │                                     
  • 3.13.0-alpine3.20          │ • Image introduces no new vulnerability but removes 120 │            │                                     
  • 3.13-alpine                │ • alpine was pulled 41K times last month                │            │                                     
  • 3.13-alpine3.20            │                                                         │            │                                     
  • 3-alpine                   │ Image details:                                          │            │                                     
  • 3-alpine3.20               │ • Size: 16 MB                                           │            │                                     
                               │ • Flavor: alpine                                        │            │                                     
                               │ • OS: 3.20                                              │            │                                     
                               │ • Runtime: 3.13.0                                       │            │                                     
                               │                                                         │            │                                     
                               │                                                         │            │                                     
                               │                                                         │            │                                     
   3.13-slim                   │ Benefits:                                               │ 1 week ago │    0C     0H     0M    25L          
  Minor runtime version update │ • Minor runtime version update                          │            │           -2     -3    -90     -4   
  Also known as:               │ • Image is smaller by 320 MB                            │            │                                     
  • 3.13.0-slim                │ • Image contains 431 fewer packages                     │            │                                     
  • 3-slim                     │ • Image introduces no new vulnerability but removes 95  │            │                                     
  • 3.13.0-slim-bookworm       │ • Tag is using slim variant                             │            │                                     
  • 3.13-slim-bookworm         │                                                         │            │                                     
  • 3-slim-bookworm            │ Image details:                                          │            │                                     
  • slim                       │ • Size: 45 MB                                           │            │                                     
  • slim-bookworm              │ • Flavor: debian                                        │            │                                     
                               │ • OS: 12                                                │            │                                     
                               │ • Runtime: 3.13.0                                       │            │                                     
                               │ • Slim: ✓                                               │            │                                     
                               │                                                         │            │                                     
                               │                                                         │            │                                     
                               │                                                         │            │                                     
   3.13                        │ Benefits:                                               │ 1 week ago │    0C     2H     3M   115L     4?   
  Tag is latest                │ • Minor runtime version update                          │            │                                     
  Also known as:               │ • Image has similar size                                │            │                                     
  • 3.13.0                     │ • Tag is latest                                         │            │                                     
  • 3                          │ • Image has same number of vulnerabilities              │            │                                     
  • 3.13.0-bookworm            │ • Image contains equal number of packages               │            │                                     
  • 3.13-bookworm              │                                                         │            │                                     
  • 3-bookworm                 │ Image details:                                          │            │                                     
  • latest                     │ • Size: 383 MB                                          │            │                                     
  • bookworm                   │ • Flavor: debian                                        │            │                                     
                               │ • OS: 12                                                │            │                                     
                               │ • Runtime: 3.13.0                                       │            │                                     
                               │                                                         │            │                                     
                               │                                                         │            │                                     
                               │                                                         │            │                                     

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

0 participants