Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Patton integration #587

Closed
iranzo opened this issue May 13, 2018 · 5 comments
Closed

Patton integration #587

iranzo opened this issue May 13, 2018 · 5 comments

Comments

@iranzo
Copy link
Member

iranzo commented May 13, 2018

https://github.com/BBVA/patton-server stores and tracks published CVE's and CPE's from NIST and can check provided package list for known issues

@iranzo
Copy link
Member Author

iranzo commented May 14, 2018

Depends on BBVA/patton-cli#4

@shatadru
Copy link
Collaborator

Hi iranzo, does this tool rely upon package version?
Actually the rpms shipped in RHEL might have different version than the upstream and can cause false positive if just rpm version is checked as many times patches are backported in older version. This is true in most package in normal rhel repos.

@shatadru
Copy link
Collaborator

shatadru commented May 14, 2018

For example we backport patches from 4.16 series kernel in older 3.10.0 kernel shipped in rhel7. So if just pckg version is checked there will be lots of false positives for RHEL.

Reference : https://access.redhat.com/security/updates/backporting

@iranzo
Copy link
Member Author

iranzo commented May 14, 2018

Yup, that was also one of my concerns and I'll have to dig it as right now it also doesn't support RPM (afaik)

@github-actions
Copy link

This issue is stale because it has been open 60 days with no activity. Remove stale label or comment or this will be closed in 7 days

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

2 participants