Have the nightly build #419
yifanfu
started this conversation in
Ideas & Feature Requests
Replies: 0 comments
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
👉 Describe the problem
We can consider to have nightly build for the image to reduce the CVEs. I have evaluated the nginx unit variant and realised we have 1 high severity CVE as shown below:
👥 Problem evidence & reach
I guess whoever cares about security would be affected. Evidence shown above.
🏆 How to solve this problem
🥰 Describe the "impact" on users?
CVEs (espacially critical and high ones) would cause some security issue to customer and potentially lead to be hacked.
💯 How do we validate the problem is solved?
Using some scanning tools like docker scout or trivy to scan the CVEs after the image been built. Fail the pipeline if critical or high CVE been detected.
Beta Was this translation helpful? Give feedback.
All reactions