question-mark
Stuck on an issue?

Lightrun Answers was designed to reduce the constant googling that comes with debugging 3rd party libraries. It collects links to all the places you might be looking at while hunting down a tough bug.

And, if you’re still stuck at the end, we’re happy to hop on a call to see how we can help out.

Security report is confusing

See original GitHub issue

I created a helm chart for SFTPGo and published it in a repository on Artifact Hub:

https://artifacthub.io/packages/helm/sagikazarmark/sftpgo/0.0.7

There are two flavors of images published for SFTPGo:

  • Debian based
  • Alpine based

Both images are added to the chart as annotations in Chart.yaml.

As one could expect, the Debian version is full of packages with reported security vulnerabilities whereas the Alpine version is all green.

When looking at the Security report, it’s a little bit confusing though, because it shows all those red signs and without a few clicks it’s not immediately obvious that there are alternative images which should be “safe” to use.

Publishing images for multiple distributions is a common practice and the “default” is often Debian and not Alpine, so it’s even more important to share that information. I don’t have any ideas how to do that though, I just wanted to raise an issue about it.

Here are some screenshots that show what I tried to describe above:

Screenshot 2020-11-12 at 19 54 46 Screenshot 2020-11-12 at 19 55 03 Screenshot 2020-11-12 at 19 55 10

Issue Analytics

  • State:closed
  • Created 3 years ago
  • Comments:9

github_iconTop GitHub Comments

1reaction
sagikazarmarkcommented, Nov 18, 2020

Thanks for the explanation! Makes sense

1reaction
sagikazarmarkcommented, Nov 13, 2020

@tegioz the new screenshot looks great, thanks!

The security badge could maybe say

128 vulnerabilities found
(in 2 images)

Or an information icon next to the summary text saying the same in a popup, pointing to the full report for details.

Read more comments on GitHub >

github_iconTop Results From Across the Web

Concepts of Risk, Safety & Security: Confusion, Conflict & Clarity
This confusion in and of itself manufactures harm, threats and impacts safety, security and risk practices, including management.
Read more >
Q3 Safety & Security Report : r/redditsecurity
We've spoken a good bit about content manipulation, and we discussed particular issues associated with abusive and hateful content, but we haven ...
Read more >
Commonly confused security topics | Infosec Resources
Commonly Confused Security Topics Working in cybersecurity and information security tests your skills and abilities, forcing you to keep ...
Read more >
How to correct confusing point or user reports, for example
How to correct confusing point or user reports, for example; points 1-9 reporting as 101-109. No ratings.
Read more >
Addressing the Confusion Around Materiality and Reporting
SASB recommends using “material” only when describing sustainability information that meets the securities law definition, and claims that its ...
Read more >

github_iconTop Related Medium Post

No results found

github_iconTop Related StackOverflow Question

No results found

github_iconTroubleshoot Live Code

Lightrun enables developers to add logs, metrics and snapshots to live code - no restarts or redeploys required.
Start Free

github_iconTop Related Reddit Thread

No results found

github_iconTop Related Hackernoon Post

No results found

github_iconTop Related Tweet

No results found

github_iconTop Related Dev.to Post

No results found

github_iconTop Related Hashnode Post

No results found