@@ -732,6 +732,7 @@ Filtered 9 local/unscannable package/s from the scan.
732
732
| https://osv.dev/CVE-2023-6129 | 6.5 | Debian | openssl | 1.1.0l-1~deb9u5 | fixtures/sbom-insecure/postgres-stretch.cdx.xml |
733
733
| https://osv.dev/CVE-2023-6237 | | Debian | openssl | 1.1.0l-1~deb9u5 | fixtures/sbom-insecure/postgres-stretch.cdx.xml |
734
734
| https://osv.dev/CVE-2024-0727 | 5.5 | Debian | openssl | 1.1.0l-1~deb9u5 | fixtures/sbom-insecure/postgres-stretch.cdx.xml |
735
+ | https://osv.dev/CVE-2024-12797 | | Debian | openssl | 1.1.0l-1~deb9u5 | fixtures/sbom-insecure/postgres-stretch.cdx.xml |
735
736
| https://osv.dev/CVE-2024-13176 | | Debian | openssl | 1.1.0l-1~deb9u5 | fixtures/sbom-insecure/postgres-stretch.cdx.xml |
736
737
| https://osv.dev/CVE-2024-2511 | | Debian | openssl | 1.1.0l-1~deb9u5 | fixtures/sbom-insecure/postgres-stretch.cdx.xml |
737
738
| https://osv.dev/CVE-2024-4603 | | Debian | openssl | 1.1.0l-1~deb9u5 | fixtures/sbom-insecure/postgres-stretch.cdx.xml |
@@ -2209,6 +2210,7 @@ Loaded OSS-Fuzz local db from <tempdir>/osv-scanner/OSS-Fuzz/all.zip
2209
2210
| https://osv.dev/CVE-2023-6129 | 6.5 | Debian | openssl | 1.1.0l-1~deb9u5 | fixtures/sbom-insecure/postgres-stretch.cdx.xml |
2210
2211
| https://osv.dev/CVE-2023-6237 | | Debian | openssl | 1.1.0l-1~deb9u5 | fixtures/sbom-insecure/postgres-stretch.cdx.xml |
2211
2212
| https://osv.dev/CVE-2024-0727 | 5.5 | Debian | openssl | 1.1.0l-1~deb9u5 | fixtures/sbom-insecure/postgres-stretch.cdx.xml |
2213
+ | https://osv.dev/CVE-2024-12797 | | Debian | openssl | 1.1.0l-1~deb9u5 | fixtures/sbom-insecure/postgres-stretch.cdx.xml |
2212
2214
| https://osv.dev/CVE-2024-13176 | | Debian | openssl | 1.1.0l-1~deb9u5 | fixtures/sbom-insecure/postgres-stretch.cdx.xml |
2213
2215
| https://osv.dev/CVE-2024-2511 | | Debian | openssl | 1.1.0l-1~deb9u5 | fixtures/sbom-insecure/postgres-stretch.cdx.xml |
2214
2216
| https://osv.dev/CVE-2024-4603 | | Debian | openssl | 1.1.0l-1~deb9u5 | fixtures/sbom-insecure/postgres-stretch.cdx.xml |
@@ -2419,6 +2421,7 @@ Loaded OSS-Fuzz local db from <tempdir>/osv-scanner/OSS-Fuzz/all.zip
2419
2421
| https://osv.dev/CVE-2023-6129 | 6.5 | Debian | openssl | 1.1.0l-1~deb9u5 | fixtures/sbom-insecure/postgres-stretch.cdx.xml |
2420
2422
| https://osv.dev/CVE-2023-6237 | | Debian | openssl | 1.1.0l-1~deb9u5 | fixtures/sbom-insecure/postgres-stretch.cdx.xml |
2421
2423
| https://osv.dev/CVE-2024-0727 | 5.5 | Debian | openssl | 1.1.0l-1~deb9u5 | fixtures/sbom-insecure/postgres-stretch.cdx.xml |
2424
+ | https://osv.dev/CVE-2024-12797 | | Debian | openssl | 1.1.0l-1~deb9u5 | fixtures/sbom-insecure/postgres-stretch.cdx.xml |
2422
2425
| https://osv.dev/CVE-2024-13176 | | Debian | openssl | 1.1.0l-1~deb9u5 | fixtures/sbom-insecure/postgres-stretch.cdx.xml |
2423
2426
| https://osv.dev/CVE-2024-2511 | | Debian | openssl | 1.1.0l-1~deb9u5 | fixtures/sbom-insecure/postgres-stretch.cdx.xml |
2424
2427
| https://osv.dev/CVE-2024-4603 | | Debian | openssl | 1.1.0l-1~deb9u5 | fixtures/sbom-insecure/postgres-stretch.cdx.xml |
@@ -3014,8 +3017,8 @@ failed to load image from tarball with path "./fixtures/oci-image/no-file-here.t
3014
3017
Scanning local image tarball "../../internal/image/fixtures/test-java-full.tar"
3015
3018
3016
3019
Container Scanning Result (Alpine Linux v3.21):
3017
- Total 12 packages affected by 16 vulnerabilities (1 Critical, 5 High, 9 Medium, 0 Low, 1 Unknown) from 2 ecosystems.
3018
- 15 vulnerabilities have fixes available.
3020
+ Total 12 packages affected by 17 vulnerabilities (1 Critical, 5 High, 9 Medium, 0 Low, 2 Unknown) from 2 ecosystems.
3021
+ 16 vulnerabilities have fixes available.
3019
3022
3020
3023
Maven
3021
3024
+-----------------------------------------------------------------------------------------------------------------------------------------+
@@ -3041,7 +3044,7 @@ Alpine:v3.21
3041
3044
| PACKAGE | INSTALLED VERSION | FIX AVAILABLE | VULN COUNT | INTRODUCED LAYER | IN BASE IMAGE |
3042
3045
+----------+-------------------+---------------+------------+------------------+-----------------+
3043
3046
| libtasn1 | 4.19.0-r2 | Fix Available | 1 | # 5 Layer | eclipse-temurin |
3044
- | openssl | 3.3.2-r4 | Fix Available | 1 | # 0 Layer | alpine |
3047
+ | openssl | 3.3.2-r4 | Fix Available | 2 | # 0 Layer | alpine |
3045
3048
+----------+-------------------+---------------+------------+------------------+-----------------+
3046
3049
3047
3050
For the most comprehensive scan results, we recommend using the HTML output: `osv-scanner scan image --serve <image_name>`.
@@ -3262,8 +3265,8 @@ Warning: `scan` exists as both a subcommand of OSV-Scanner and as a file on the
3262
3265
Scanning local image tarball "../../internal/image/fixtures/test-node_modules-npm-empty.tar"
3263
3266
3264
3267
Container Scanning Result (Alpine Linux v3.19):
3265
- Total 2 packages affected by 10 vulnerabilities (0 Critical, 0 High, 4 Medium, 0 Low, 6 Unknown) from 1 ecosystems.
3266
- 10 vulnerabilities have fixes available.
3268
+ Total 2 packages affected by 11 vulnerabilities (0 Critical, 0 High, 4 Medium, 0 Low, 7 Unknown) from 1 ecosystems.
3269
+ 11 vulnerabilities have fixes available.
3267
3270
3268
3271
Alpine:v3.19
3269
3272
+---------------------------------------------------------------------------------------------+
@@ -3272,7 +3275,7 @@ Alpine:v3.19
3272
3275
| PACKAGE | INSTALLED VERSION | FIX AVAILABLE | VULN COUNT | INTRODUCED LAYER | IN BASE IMAGE |
3273
3276
+---------+-------------------+---------------+------------+------------------+---------------+
3274
3277
| busybox | 1.36.1-r15 | Fix Available | 4 | # 0 Layer | alpine |
3275
- | openssl | 3.1.4-r5 | Fix Available | 6 | # 0 Layer | alpine |
3278
+ | openssl | 3.1.4-r5 | Fix Available | 7 | # 0 Layer | alpine |
3276
3279
+---------+-------------------+---------------+------------+------------------+---------------+
3277
3280
3278
3281
For the most comprehensive scan results, we recommend using the HTML output: `osv-scanner scan image --serve <image_name>`.
@@ -3289,8 +3292,8 @@ Warning: `scan` exists as both a subcommand of OSV-Scanner and as a file on the
3289
3292
Scanning local image tarball "../../internal/image/fixtures/test-node_modules-npm-full.tar"
3290
3293
3291
3294
Container Scanning Result (Alpine Linux v3.19):
3292
- Total 4 packages affected by 13 vulnerabilities (2 Critical, 0 High, 5 Medium, 0 Low, 6 Unknown) from 2 ecosystems.
3293
- 12 vulnerabilities have fixes available.
3295
+ Total 4 packages affected by 14 vulnerabilities (2 Critical, 0 High, 5 Medium, 0 Low, 7 Unknown) from 2 ecosystems.
3296
+ 13 vulnerabilities have fixes available.
3294
3297
3295
3298
npm
3296
3299
+-------------------------------------------------------------------------------------------------+
@@ -3308,7 +3311,7 @@ Alpine:v3.19
3308
3311
| PACKAGE | INSTALLED VERSION | FIX AVAILABLE | VULN COUNT | INTRODUCED LAYER | IN BASE IMAGE |
3309
3312
+---------+-------------------+---------------+------------+------------------+---------------+
3310
3313
| busybox | 1.36.1-r15 | Fix Available | 4 | # 0 Layer | alpine |
3311
- | openssl | 3.1.4-r5 | Fix Available | 6 | # 0 Layer | alpine |
3314
+ | openssl | 3.1.4-r5 | Fix Available | 7 | # 0 Layer | alpine |
3312
3315
+---------+-------------------+---------------+------------+------------------+---------------+
3313
3316
3314
3317
For the most comprehensive scan results, we recommend using the HTML output: `osv-scanner scan image --serve <image_name>`.
@@ -3325,8 +3328,8 @@ Warning: `scan` exists as both a subcommand of OSV-Scanner and as a file on the
3325
3328
Scanning local image tarball "../../internal/image/fixtures/test-node_modules-pnpm-empty.tar"
3326
3329
3327
3330
Container Scanning Result (Alpine Linux v3.19):
3328
- Total 2 packages affected by 10 vulnerabilities (0 Critical, 0 High, 4 Medium, 0 Low, 6 Unknown) from 1 ecosystems.
3329
- 10 vulnerabilities have fixes available.
3331
+ Total 2 packages affected by 11 vulnerabilities (0 Critical, 0 High, 4 Medium, 0 Low, 7 Unknown) from 1 ecosystems.
3332
+ 11 vulnerabilities have fixes available.
3330
3333
3331
3334
Alpine:v3.19
3332
3335
+---------------------------------------------------------------------------------------------+
@@ -3335,7 +3338,7 @@ Alpine:v3.19
3335
3338
| PACKAGE | INSTALLED VERSION | FIX AVAILABLE | VULN COUNT | INTRODUCED LAYER | IN BASE IMAGE |
3336
3339
+---------+-------------------+---------------+------------+------------------+---------------+
3337
3340
| busybox | 1.36.1-r15 | Fix Available | 4 | # 0 Layer | alpine |
3338
- | openssl | 3.1.4-r5 | Fix Available | 6 | # 0 Layer | alpine |
3341
+ | openssl | 3.1.4-r5 | Fix Available | 7 | # 0 Layer | alpine |
3339
3342
+---------+-------------------+---------------+------------+------------------+---------------+
3340
3343
3341
3344
For the most comprehensive scan results, we recommend using the HTML output: `osv-scanner scan image --serve <image_name>`.
@@ -3352,8 +3355,8 @@ Warning: `scan` exists as both a subcommand of OSV-Scanner and as a file on the
3352
3355
Scanning local image tarball "../../internal/image/fixtures/test-node_modules-pnpm-full.tar"
3353
3356
3354
3357
Container Scanning Result (Alpine Linux v3.19):
3355
- Total 2 packages affected by 10 vulnerabilities (0 Critical, 0 High, 4 Medium, 0 Low, 6 Unknown) from 1 ecosystems.
3356
- 10 vulnerabilities have fixes available.
3358
+ Total 2 packages affected by 11 vulnerabilities (0 Critical, 0 High, 4 Medium, 0 Low, 7 Unknown) from 1 ecosystems.
3359
+ 11 vulnerabilities have fixes available.
3357
3360
3358
3361
Alpine:v3.19
3359
3362
+---------------------------------------------------------------------------------------------+
@@ -3362,7 +3365,7 @@ Alpine:v3.19
3362
3365
| PACKAGE | INSTALLED VERSION | FIX AVAILABLE | VULN COUNT | INTRODUCED LAYER | IN BASE IMAGE |
3363
3366
+---------+-------------------+---------------+------------+------------------+---------------+
3364
3367
| busybox | 1.36.1-r15 | Fix Available | 4 | # 0 Layer | alpine |
3365
- | openssl | 3.1.4-r5 | Fix Available | 6 | # 0 Layer | alpine |
3368
+ | openssl | 3.1.4-r5 | Fix Available | 7 | # 0 Layer | alpine |
3366
3369
+---------+-------------------+---------------+------------+------------------+---------------+
3367
3370
3368
3371
For the most comprehensive scan results, we recommend using the HTML output: `osv-scanner scan image --serve <image_name>`.
@@ -3379,8 +3382,8 @@ Warning: `scan` exists as both a subcommand of OSV-Scanner and as a file on the
3379
3382
Scanning local image tarball "../../internal/image/fixtures/test-node_modules-yarn-empty.tar"
3380
3383
3381
3384
Container Scanning Result (Alpine Linux v3.19):
3382
- Total 2 packages affected by 10 vulnerabilities (0 Critical, 0 High, 4 Medium, 0 Low, 6 Unknown) from 1 ecosystems.
3383
- 10 vulnerabilities have fixes available.
3385
+ Total 2 packages affected by 11 vulnerabilities (0 Critical, 0 High, 4 Medium, 0 Low, 7 Unknown) from 1 ecosystems.
3386
+ 11 vulnerabilities have fixes available.
3384
3387
3385
3388
Alpine:v3.19
3386
3389
+---------------------------------------------------------------------------------------------+
@@ -3389,7 +3392,7 @@ Alpine:v3.19
3389
3392
| PACKAGE | INSTALLED VERSION | FIX AVAILABLE | VULN COUNT | INTRODUCED LAYER | IN BASE IMAGE |
3390
3393
+---------+-------------------+---------------+------------+------------------+---------------+
3391
3394
| busybox | 1.36.1-r15 | Fix Available | 4 | # 0 Layer | alpine |
3392
- | openssl | 3.1.4-r5 | Fix Available | 6 | # 0 Layer | alpine |
3395
+ | openssl | 3.1.4-r5 | Fix Available | 7 | # 0 Layer | alpine |
3393
3396
+---------+-------------------+---------------+------------+------------------+---------------+
3394
3397
3395
3398
For the most comprehensive scan results, we recommend using the HTML output: `osv-scanner scan image --serve <image_name>`.
@@ -3406,8 +3409,8 @@ Warning: `scan` exists as both a subcommand of OSV-Scanner and as a file on the
3406
3409
Scanning local image tarball "../../internal/image/fixtures/test-node_modules-yarn-full.tar"
3407
3410
3408
3411
Container Scanning Result (Alpine Linux v3.19):
3409
- Total 2 packages affected by 10 vulnerabilities (0 Critical, 0 High, 4 Medium, 0 Low, 6 Unknown) from 1 ecosystems.
3410
- 10 vulnerabilities have fixes available.
3412
+ Total 2 packages affected by 11 vulnerabilities (0 Critical, 0 High, 4 Medium, 0 Low, 7 Unknown) from 1 ecosystems.
3413
+ 11 vulnerabilities have fixes available.
3411
3414
3412
3415
Alpine:v3.19
3413
3416
+---------------------------------------------------------------------------------------------+
@@ -3416,7 +3419,7 @@ Alpine:v3.19
3416
3419
| PACKAGE | INSTALLED VERSION | FIX AVAILABLE | VULN COUNT | INTRODUCED LAYER | IN BASE IMAGE |
3417
3420
+---------+-------------------+---------------+------------+------------------+---------------+
3418
3421
| busybox | 1.36.1-r15 | Fix Available | 4 | # 0 Layer | alpine |
3419
- | openssl | 3.1.4-r5 | Fix Available | 6 | # 0 Layer | alpine |
3422
+ | openssl | 3.1.4-r5 | Fix Available | 7 | # 0 Layer | alpine |
3420
3423
+---------+-------------------+---------------+------------+------------------+---------------+
3421
3424
3422
3425
For the most comprehensive scan results, we recommend using the HTML output: `osv-scanner scan image --serve <image_name>`.
0 commit comments