Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Critical vulnerability for rack 0.0.0 in docker-scout #501

Closed
IainMcHugh opened this issue Apr 25, 2024 · 2 comments
Closed

Critical vulnerability for rack 0.0.0 in docker-scout #501

IainMcHugh opened this issue Apr 25, 2024 · 2 comments
Labels
bug Indicates an unexpected problem or unintended behavior

Comments

@IainMcHugh
Copy link

Hello

I am currently using "@pact-foundation/pact": "^12.3.0" as a dev dependency in a NextJS project. Docker-scout is listing a critical vulnerability for rack 0.0.0 , and the package path is:

Type: gem
Location:
/node_modules/@pact-foundation/pact-core/standalone/darwin-arm64-2.4.2/pact/lib/vendor/ruby/3.2.0/gems/rack-2.2.8.1/rack.gemspec
/node_modules/@pact-foundation/pact-core/standalone/darwin-x64-2.4.2/pact/lib/vendor/ruby/3.2.0/gems/rack-2.2.8.1/rack.gemspec
/node_modules/@pact-foundation/pact-core/standalone/linux-arm64-2.4.2/pact/lib/vendor/ruby/3.2.0/gems/rack-2.2.8.1/rack.gemspec
/node_modules/@pact-foundation/pact-core/standalone/linux-x64-2.4.2/pact/lib/vendor/ruby/3.2.0/gems/rack-2.2.8.1/rack.gemspec
/node_modules/@pact-foundation/pact-core/standalone/windows-x64-2.4.2/pact/lib/vendor/ruby/3.2.0/gems/rack-2.2.8.1/rack.gemspec
We upgraded the @pact-foundation/pact version based on pact-foundation/pact-ruby-standalone#132 issue hoping it would fix this but the location is linking back to @pact-foundation/pact-core

@IainMcHugh IainMcHugh added the bug Indicates an unexpected problem or unintended behavior label Apr 25, 2024
@YOU54F
Copy link
Member

YOU54F commented Apr 25, 2024

its suspect that docker-scout is complaining incorrectly about the rack version 0.0.0 when its at 2.2.8.1, which was the most recent patched version for rack in the 2.x release branch

@YOU54F
Copy link
Member

YOU54F commented Jun 12, 2024

Closing due to lack of response, and I also think the report is invalid as per previous comments

@YOU54F YOU54F closed this as completed Jun 12, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug Indicates an unexpected problem or unintended behavior
Projects
None yet
Development

No branches or pull requests

2 participants