Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Missing Version Specification In dnf install @ /build-environment/Dockerfile #4

Open
nleach999 opened this issue Jun 9, 2023 · 0 comments

Comments

@nleach999
Copy link
Collaborator

nleach999 commented Jun 9, 2023

Checkmarx (IaC-Security): Missing Version Specification In dnf install
Checkmarx Project: checkmarx-ts/cx-supply-chain-toolkit
Repository URL: https://github.com/checkmarx-ts/cx-supply-chain-toolkit
Branch: master
Scan ID: 1d2e98e3-6db0-4376-8620-c9ac41d3ec76


Specifying a package version allows to reduce failures due to unanticipated changes in required packages.

Locations:

Result 1:
Severity: MEDIUM
State: CONFIRMED
Status: RECURRENT
    File: /build-environment/Dockerfile[138,0]
    Expected value: Package version should be specified when using 'dnf install'
    Actual value: Package version should be pinned when running ´dnf install´
    Review result in Checkmarx One: Missing Version Specification In dnf install

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

1 participant