Skip to content
New issue

Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? # to your account

Vulnerability Found #45

Closed
rmauc opened this issue Jun 16, 2020 · 7 comments
Closed

Vulnerability Found #45

rmauc opened this issue Jun 16, 2020 · 7 comments
Milestone

Comments

@rmauc
Copy link

rmauc commented Jun 16, 2020

Hello
I am very interested in using the Ansible Sonarqube plugin (which has a dependency on this plugin).
However, our security guys ran an XRay scan and found a high vulnerability for qos.logback (attached)

yamlplugin
.
Would you be able to take a look to determine if you can patch and release a newer version?
That would be very much appreciated if at all possible
Thanks in advance

@sbaudoin
Copy link
Owner

Hello,

Yes, I think I can change that. However I don't know how to check that my fix will be OK: do you know how I could do that?

@rmauc
Copy link
Author

rmauc commented Jun 17, 2020

Hi
Thanks for getting back to me. I can get my guy to rerun the scan :)

@rmauc
Copy link
Author

rmauc commented Jul 7, 2020

Hello
Do you have anything to test?
Thanks again

@sbaudoin
Copy link
Owner

Hello,

I think it's better if I can check myself the errors: going back and forth with small code change may not be efficient. So is there a way for me to check if my fix is correct?

@sbaudoin sbaudoin added this to the 1.5.2 milestone Nov 8, 2020
@sbaudoin
Copy link
Owner

sbaudoin commented Nov 8, 2020

107935b updates the logback dependency to 1.2.3. Hope this is sufficient.

@sbaudoin sbaudoin mentioned this issue Nov 8, 2020
@reitzmichnicht
Copy link

You can run snyk on your project which should give you the results you expect

@sbaudoin
Copy link
Owner

sbaudoin commented Nov 9, 2020

Thanks. Snyk does not report issue for this project

# for free to join this conversation on GitHub. Already have an account? # to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants