Inedo Community Forums Forums
    • Recent
    • Tags
    • Popular
    • Login

    Welcome to the Inedo Forums! Check out the Forums Guide for help getting started.

    If you are experiencing any issues with the forum software, please visit the Contact Form on our website and let us know!

    BUG: ProGet Vulnerablity Listing

    Scheduled Pinned Locked Moved Support
    10 Posts 3 Posters 33 Views 1 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • S Offline
      scroak_6473
      last edited by

      Hi Guys,

      Pretty sure this is a bug, I'm running ProGet v5.3.7 as a docker container.

      Clicking on "Vulnerabilities" in the top navigation bar lists all discovered vulnerabilities. However in the package column it displays the package digest, not the name. It would be great if we could have the name instead.

      8ca4def7-4364-483f-9a44-1fab26025276-image.png

      Thanks

      Simon

      1 Reply Last reply Reply Quote 0
      • rhessingerR Offline
        rhessinger inedo-engineer
        last edited by

        Hi @scroak_6473,

        This works as designed. Clair attaches a vulnerability at the Docker image layer, not at the image itself. This also means that that vulnerability can exist across multiple images because Docker will share layers between images.

        Thanks,
        Rich

        Products Engineer, Inedo

        1 Reply Last reply Reply Quote 0
        • S Offline
          scroak_6473
          last edited by

          Thanks @rhessinger

          If that is the case then perhaps this view could have an extra column detailing the package this layer (and vulnerability) exists in?

          The use case I have:

          • I've just connected my docker registry feed to a Vulnerablity scanner source
          • I have no way of finding out a "summary" of which packages/images in my feed have Vulnerabilities in them without clicking each repo and then clicking the "Vulnerabilities" tab
          • Additionally if a developer uploads an image to the repo, that contains a new vulnerability how do I see this / get notified of this without checking each repo manually?

          Thanks

          Simon

          1 Reply Last reply Reply Quote 0
          • atrippA Offline
            atripp inedo-engineer
            last edited by

            Thanks, you have have a pretty good point here. Finding where the vulnerabilities live is kind of difficult, but let's make it easier 😄

            First, bc9ab73e5b14 is a layer that's in one or more container images that has zero or more tags in a repository (in a registry/feed).

            What's actually useful information is registry (feed), then repository+tag (containername:version).

            If all this added up to a single tag in a single registry + repository + tag combination, we could display that instead. But there are going to be a lot of container images using that layer...

            Maybe clicking that page opens up a page that is like, "tags that use this layer" or something, and it displays Registry (Feed) and REpository+Tag in a simple list view?

            The only way to get to this page would be clicking on a image hash like that, so perhaps it could be a modal-popup window instead?

            Just brainstorming... what do you think?

            S 1 Reply Last reply Reply Quote 0
            • S Offline
              scroak_6473 @atripp
              last edited by

              Hi @atripp

              I like your "tags that use this layer" suggestion, I was also thinking you could do something like this mock-up within the repo view:

              a0a5b615-b120-408f-828d-a750d48dacfa-image.png

              In addition you could also improve the "feed view" with some more information about the number of tags/images & vulnerablities per repo like this:

              d8a7bb14-b6c6-4676-b5b6-11d25523bb2d-image.png

              Or even:

              262b93e8-7f06-4048-a50a-afe0935abadb-image.png

              atrippA 1 Reply Last reply Reply Quote 1
              • atrippA Offline
                atripp inedo-engineer @scroak_6473
                last edited by

                @scroak_6473 great suggestions, thanks!! The mockups will really help me to present a case :)

                I see that the priority is on finding the unassessed vulnerabilities, which make sense. I don't know about a "mouseover" (we don't have this UI construct in our products like this to make this easily doable), but I can envision a modal window (popup) or a regular page that allows for quickly asessing those vulnerabilities 🤔

                This isn't trivial, but it's not terribly complicated either. I'm going to try to get this submitted internally next week (I'll share what I write up), and from there we might be able to get this in the following or near-term maintence release 😄

                S 1 Reply Last reply Reply Quote 0
                • S Offline
                  scroak_6473 @atripp
                  last edited by

                  Amazing thanks @atripp

                  Let me know what version this appears in I would love to try it out.

                  Thanks

                  Simon

                  1 Reply Last reply Reply Quote 0
                  • atrippA Offline
                    atripp inedo-engineer
                    last edited by

                    Great!! I've logged this as PG-1798, and it's planned for 5.3.10 (Aug 28), but may get delayed depending on other priories.

                    1 Reply Last reply Reply Quote 0
                    • rhessingerR Offline
                      rhessinger inedo-engineer
                      last edited by

                      Hi @scroak_6473,

                      I just wanted to send over a few screenshots so you can see what is releasing tomorrow:

                      When you click on the layer digest on the Vulnerabilities, Repository Vulnerabilities, and Image Vulnerabilities pages, it now will show this modal dialog:
                      d8f586f2-0fa8-451b-871b-9d813560fb3c-image.png

                      The List Repositories page now looks like this:
                      b425be2a-8723-40a4-9eb2-8a63e6d71d08-image.png

                      The All Tags for a Repository now looks like this:
                      04425be1-6a75-4a7d-85c8-9b9c813cefd3-image.png

                      The All Images for a Repository looks like this:
                      88b48439-5af7-4f53-8879-4a2cbec9fcc5-image.png

                      Thanks,
                      Rich

                      Products Engineer, Inedo

                      S 1 Reply Last reply Reply Quote 0
                      • S Offline
                        scroak_6473 @rhessinger
                        last edited by

                        That's amazing! Thanks so much @rhessinger

                        You guys rock!

                        1 Reply Last reply Reply Quote 0

                        Hello! It looks like you're interested in this conversation, but you don't have an account yet.

                        Getting fed up of having to scroll through the same posts each visit? When you register for an account, you'll always come back to exactly where you were before, and choose to be notified of new replies (either via email, or push notification). You'll also be able to save bookmarks and upvote posts to show your appreciation to other community members.

                        With your input, this post could be even better 💗

                        Register Login
                        • 1 / 1
                        • First post
                          Last post
                        Inedo Website Home • Support Home • Code of Conduct • Forums Guide • Documentation