Skip to content

CVE scans incorrectly claim that e.g., Alpine git package is included in EVE images #5473

@eriknordmark

Description

@eriknordmark

Describe the unexpected behaviour

CVE scanners which use the SBoM see that some version of git is included in the image.
Turns out this is coming from lib/apk/db/installed which is collected by the linuxkit build and also placed in /lib/apk/db/installed in the final EVE image.

The particular issue with git has been tracked down to come from linuxkit/runc introduced by linuxkit/linuxkit#3913 and there are similar ones where Alpine packages like gcc, make, etc appear in apk/db/installed even though there is no content from those packages included in the EVE image.

It is useful to have the information from the apk/db/installed since it include package versions, but in these cases it seems problematic to use it as the authoritative source of which package content is included in the containers.

Metadata

Metadata

Assignees

Labels

No labels
No labels

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions