Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Apt Get Install Pin Version Not Defined @ /build-environment/Dockerfile #35

Open
nleach999 opened this issue Jun 21, 2023 · 0 comments
Open

Comments

@nleach999
Copy link
Collaborator

nleach999 commented Jun 21, 2023

Checkmarx (IaC-Security): Apt Get Install Pin Version Not Defined
Checkmarx Project: checkmarx-ts/cx-supply-chain-toolkit
Repository URL: https://github.com/checkmarx-ts/cx-supply-chain-toolkit
Branch: master
Scan ID: 1d2e98e3-6db0-4376-8620-c9ac41d3ec76


When installing a package, its pin version should be defined

Locations:

Result 1:
Severity: MEDIUM
State: TO_VERIFY
Status: RECURRENT
    File: /build-environment/Dockerfile[103,0]
    Expected value: Package 'adduser' has version defined
    Actual value: Package 'adduser' does not have version defined
    Review result in Checkmarx One: Apt Get Install Pin Version Not Defined

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

1 participant