Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

ORT Docker File :: Security Vulnerability Identified #9084

Open
porsche-rishisaxena opened this issue Sep 5, 2024 · 2 comments
Open

ORT Docker File :: Security Vulnerability Identified #9084

porsche-rishisaxena opened this issue Sep 5, 2024 · 2 comments
Labels
docker About Docker topics enhancement Issues that are considered to be enhancements

Comments

@porsche-rishisaxena
Copy link

Describe the bug

Docker Image of ORT stored in AWS ECR detected with security vulnerabilities

Expected behavior

Resolve or have minimal vulnerabilities to be compliant from security standpoint

Console / log output

Please find attached report
vulnerabilities.xlsx

Environment

Docker Image hosted on AWS ECR

@porsche-rishisaxena porsche-rishisaxena added bug Issues that are considered to be bugs to triage Issues that need triaging labels Sep 5, 2024
@sschuberth
Copy link
Member

Docker Image of ORT stored in AWS ECR detected with security vulnerabilities

Could you please share which tool was using to identify these vulnerabilities, for reference?

@sschuberth sschuberth added enhancement Issues that are considered to be enhancements docker About Docker topics and removed bug Issues that are considered to be bugs to triage Issues that need triaging labels Sep 5, 2024
@porsche-rishisaxena
Copy link
Author

@sschuberth AWS Inspector 2 is used for discovering security vulnerabilities. Please refer to this document: https://docs.aws.amazon.com/inspector/latest/user/what-is-inspector.html

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
docker About Docker topics enhancement Issues that are considered to be enhancements
Projects
None yet
Development

No branches or pull requests

2 participants