Replies: 1 comment 1 reply
-
|
Our images are built on an existing image ( |
Beta Was this translation helpful? Give feedback.
1 reply
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
-
Hi,
I've been tinkering with PowerDNS for a while now, and noticed that the "official" Docker images contain vulnerabilities (at least, according to Trivy when I pulled the images through it). And while the reports from these types of scans aren't always on correct (e.g. false positives), it did make me wonder! As I could conclude that there are extra packages included in said images, whereas the PowerDNS binary itself only has a select number of packages as a requirement.
So I was wondering/curious, is there a reason why the "official" Docker images contain these extra packages, and why the vulnerabilities aren't mitigated once observed?
Beta Was this translation helpful? Give feedback.
All reactions