Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

First attempt using intel/cve-bin-tool to scan for CVEs during build. #3460

Closed
wants to merge 2 commits into from

Conversation

mitchell-as
Copy link
Contributor

@mitchell-as mitchell-as commented Aug 22, 2024

TaskDX-2978 We have a test that verifies we aren't shipping with CVEs

The tool found CVEs in our sqlite implementation, so I updated it. However, it's a ~3.5M line diff 😢

@mitchell-as mitchell-as force-pushed the mitchell/dx-2978 branch 18 times, most recently from d889df4 to cb5f17e Compare August 26, 2024 18:32
@mitchell-as mitchell-as changed the title First attempt using intel/cve-bin-tool-action to scan for CVE on push. First attempt using intel/cve-bin-tool to scan for CVEs during build. Aug 26, 2024
@mitchell-as
Copy link
Contributor Author

Closing, as we're going to use trivy. This scanner has false-positives and takes 6 minutes to run.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant