Skip to content

What is the cadence for wolfi-base builds to include vulnerability patches? #20739

Answered by xnox
csbuild-c7ks7s asked this question in Q&A
Discussion options

You must be logged in to vote

the package and CVE is fixed; but the issues remain with advisory data that we publish; and how/when the scanners consume it. As an example, in worst case scenario, there can be up to 48h lag in advisory data in grype. I don't know about Anchore and Trivy. And there could have been impressions in the advisory data. It is the weekend now, bu the advisories data team will pick this up on Monday - if the scanners don't improve during that time (as in get their advisory data upgraded, and rescanning existing images from days ago would result in them no longer flagged as vulnerable).

I wish there was ability to include advisory data inside the package SBOM such that without refreshing vendor a…

Replies: 1 comment 7 replies

Comment options

You must be logged in to vote
7 replies
@csbuild-c7ks7s
Comment options

@xnox
Comment options

@csbuild-c7ks7s
Comment options

@xnox
Comment options

Answer selected by csbuild-c7ks7s
@xnox
Comment options

@csbuild-c7ks7s
Comment options

@xnox
Comment options

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants