Inedo Community Forums Forums
    • Recent
    • Tags
    • Popular
    • Login

    Welcome to the Inedo Forums! Check out the Forums Guide for help getting started.

    If you are experiencing any issues with the forum software, please visit the Contact Form on our website and let us know!

    ProGet Container Image - Vulnerabilities Unassessed

    Scheduled Pinned Locked Moved Support
    4 Posts 2 Posters 17 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • A Offline
      antonio.oliveira_8481
      last edited by

      My organization is in the process of evaluating ProGet, which we would be looking to run as a Linux container. As part of the security evaluation we noticed that all of the vulnerabilities of the latest container version (https://proget.inedo.com/containers/tags/ProductImages/inedo/proget/25.0.10-ci.9/vulnerabilities at the time of writing), as well as earlier container versions listed, are labelled as "? Unassessed". Is there a reason for this?

      stevedennisS 1 Reply Last reply Reply Quote 0
      • stevedennisS Offline
        stevedennis inedo-engineer @antonio.oliveira_8481
        last edited by

        Hi @antonio-oliveira_8481 ,

        proget.inedo.com points to one of our edge node in an ProGet Edge Computing Edition network and is continuously replicating content from our hub server. Currently, we do not support replicating "non-content" (i.e. vulnerability assessments, license assignments, policies, etc.) -- only packages, containers, and assets.

        Technically... that vulnerability information should not be displayed at all, since we disabled the feature on the feed. So that must be a bug of some kind.

        Long story short, please disregard - we check all this on our central hub, but it's just not replicated to edge nodes.

        Thanks,
        Steve

        1 Reply Last reply Reply Quote 0
        • A Offline
          antonio.oliveira_8481
          last edited by

          Thanks for the response. Does that mean that the container is not susceptible to these vulnerabilities, or that you have assessed the vulnerabilities, but that this assessment status has not been replicated? Based on the package list (https://proget.inedo.com/containers/tags/ProductImages/inedo/proget/25.0.10-ci.9/packages), and the vulnerability details, it would appear that most may be relevant, at least from a package content perspective.

          stevedennisS 1 Reply Last reply Reply Quote 0
          • stevedennisS Offline
            stevedennis inedo-engineer @antonio.oliveira_8481
            last edited by

            Hi @antonio-oliveira_8481 ,

            We have already assessed the vulnerabilities; the container image is not susceptible to any of these vulnerabilities. Only two ports are exposed on the container (for http/https) and the overwhelming majority of packages built-in to the base container image (debian) are not used.

            Thanks,
            Steve

            1 Reply Last reply Reply Quote 0

            Hello! It looks like you're interested in this conversation, but you don't have an account yet.

            Getting fed up of having to scroll through the same posts each visit? When you register for an account, you'll always come back to exactly where you were before, and choose to be notified of new replies (either via email, or push notification). You'll also be able to save bookmarks and upvote posts to show your appreciation to other community members.

            With your input, this post could be even better 💗

            Register Login
            • 1 / 1
            • First post
              Last post
            Inedo Website Home • Support Home • Code of Conduct • Forums Guide • Documentation