fix(ci): qa:apache-server-scannerci #1750
Open
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
example failure
The vulns listed in the test cases associated with
cron
andubuntu:14.04
in imagequay.io/rhacs-eng/qa:apache-server-scannerci
are no longer found. The test case has been updated to check for vulns from a different package.The new vulns were chosen at random from the scan results (reviewers please share if there is a reason this particular test case exists and if different vulns should be chosen, of note the new vulns have
fixedBy
's but the old ones did not)By inspecting the last 'genesis dump' from CI for one of the vulns in question confirmed it is no longer listed for
ubuntu:14.04
:Compared to the genesis dump for StackRox 4.6.1, the vuln is indeed listed for
ubuntu:14.04
:It appears that future new genesis dumps (CI creates a new one every run) will not contain this vuln for
ubuntu:14.04
.The Ubuntu page for CVE-2017-9525 shows this:
The status of the spot checked vuln was changed on Dec 18th to
ignored
(thanks for finding that @RTann ) which will cause the vuln to be omitted from Scanners vuln feeds.