Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Supporting mageia Linux images #177

Open
juanluisbaptiste opened this issue Feb 13, 2025 · 4 comments
Open

Supporting mageia Linux images #177

juanluisbaptiste opened this issue Feb 13, 2025 · 4 comments
Assignees
Labels
enhancement New feature or request

Comments

@juanluisbaptiste
Copy link

Hi,

I'm the maintainer of the mageia Linux images, and I noticed that the security scan in Docker Hub reports no vulnerabilities for them. What can be done so these images are properly scanned?

Thanks in advance.

@cdupuis
Copy link
Collaborator

cdupuis commented Mar 4, 2025

@juanluisbaptiste, for Scout to properly report CVEs, a distribution needs to provide its own CVE feed and that CVE feed needs to be processed by the Scout backend on a regular basis. Do you have a CVE feed for mageia packages available?

@cdupuis cdupuis self-assigned this Mar 4, 2025
@dfandrich
Copy link

Yes, we have a feed in OSV format available via https://advisories.mageia.org/infos.html. It's also being pulled in to https://osv.dev/

@cdupuis
Copy link
Collaborator

cdupuis commented Mar 4, 2025

Awesome, let me take a look.

Could you provide some links to Docker Hub images that I could test this with?

@dfandrich
Copy link

Our images are at https://hub.docker.com/_/mageia The "9" tag is our latest (and only currently supported image) and was rebuilt fairly recently so might not have any (or very many) current security issues. The "cauldron" tag is for our other live distro but it's considered for development only and we don't publish advisories for it. The other numeric tags should also be working since they are our older public versions, but we no longer publish vulnerabilities for them (since they are no longer supported).

@cdupuis cdupuis added the enhancement New feature or request label Mar 4, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New feature or request
Projects
None yet
Development

No branches or pull requests

3 participants