Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

scvi-tools Vulnerability Analysis #135

Open
github-actions bot opened this issue Oct 29, 2024 · 0 comments
Open

scvi-tools Vulnerability Analysis #135

github-actions bot opened this issue Oct 29, 2024 · 0 comments

Comments

@github-actions
Copy link

Significant issues present in bwa, see quickview and recommendations below, but run CVE analysis locally.



  Target             │  getwilds/scvi-tools:latest  │    2C     0H     0M    28L   
    digest           │  bac0838ae850                │                              
  Base image         │  python:3.12-slim            │    0C     0H     0M    28L   
  Updated base image │  python:3.13-slim            │    0C     0H     0M    25L   
                     │                              │                         -3   

What's next:
    View vulnerabilities → docker scout cves getwilds/scvi-tools:latest
    View base image update recommendations → docker scout recommendations getwilds/scvi-tools:latest
    Include policy results in your quickview by supplying an organization → docker scout quickview getwilds/scvi-tools:latest --org <organization>



  Target   │  getwilds/scvi-tools:latest   
    digest │  bac0838ae850                 

## Recommended fixes

  Base image is  python:3.12-slim 

  Name            │  3.12-slim                                                                 
  Digest          │  sha256:311c6c7090a52874c9118ad17dc95cd7d030dd8ec13ab96fe23f26b8e74a3823   
  Vulnerabilities │    0C     0H     0M    28L                                                 
  Pushed          │ 1 week ago                                                                 
  Size            │ 46 MB                                                                      
  Packages        │ 156                                                                        
  Flavor          │ debian                                                                     
  OS              │ 12                                                                         
  Runtime         │ 3.12.7                                                                     
  Slim            │ ✓                                                                          

                                                                    
  │ The base image is also available under the supported tag(s)     
  `3.12-                                                            
  │ slim-bookworm`, `3.12.7-slim`, `3.12.7-slim-bookworm`. If you want
  to                                                                
  │ display recommendations specifically for a different tag, please
  │ re-run the command using the `--tag` flag.                       



Refresh base image
  Rebuild the image using a newer base image version. Updating this may result in breaking changes.

  ✓ This image version is up to date.


Change base image
  The list displays new recommended tags in descending order, where the top results are rated as most suitable.


              Tag              │                        Details                         │   Pushed   │          Vulnerabilities            
───────────────────────────────┼────────────────────────────────────────────────────────┼────────────┼─────────────────────────────────────
   3.13-slim                   │ Benefits:                                              │ 1 week ago │    0C     0H     0M    25L          
  Minor runtime version update │ • Same OS detected                                     │            │                         -3          
  Also known as:               │ • Minor runtime version update                         │            │                                     
  • 3.13.0-slim                │ • Image is smaller by 1.0 MB                           │            │                                     
  • 3-slim                     │ • Image contains 12 fewer packages                     │            │                                     
  • 3.13.0-slim-bookworm       │ • Image introduces no new vulnerability but removes 3  │            │                                     
  • 3.13-slim-bookworm         │ • Tag is using slim variant                            │            │                                     
  • 3-slim-bookworm            │                                                        │            │                                     
  • slim                       │ Image details:                                         │            │                                     
  • slim-bookworm              │ • Size: 45 MB                                          │            │                                     
                               │ • Flavor: debian                                       │            │                                     
                               │ • OS: 12                                               │            │                                     
                               │ • Runtime: 3.13.0                                      │            │                                     
                               │ • Slim: ✓                                              │            │                                     
                               │                                                        │            │                                     
                               │                                                        │            │                                     
                               │                                                        │            │                                     
   alpine                      │ Benefits:                                              │ 1 week ago │    0C     0H     0M     0L     1?   
  Tag is preferred tag         │ • Minor runtime version update                         │            │                        -28     +1   
  Also known as:               │ • Image is smaller by 28 MB                            │            │                                     
  • alpine3.20                 │ • Image contains 115 fewer packages                    │            │                                     
  • 3.13.0-alpine              │ • Tag is preferred tag                                 │            │                                     
  • 3.13.0-alpine3.20          │ • Image introduces no new vulnerability but removes 28 │            │                                     
  • 3.13-alpine                │ • alpine was pulled 41K times last month               │            │                                     
  • 3.13-alpine3.20            │                                                        │            │                                     
  • 3-alpine                   │ Image details:                                         │            │                                     
  • 3-alpine3.20               │ • Size: 16 MB                                          │            │                                     
                               │ • Flavor: alpine                                       │            │                                     
                               │ • OS: 3.20                                             │            │                                     
                               │ • Runtime: 3.13.0                                      │            │                                     
                               │                                                        │            │                                     
                               │                                                        │            │                                     
                               │                                                        │            │                                     

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

0 participants