Skip to content
Discussion options

You must be logged in to vote
  • We supply container SBOMs here.
  • You can find the EJBCA SBOM here.
  • EJBCA publishes CVEs.

CVE scans always comes with work for the person who scans, while the base image is updated for each feature release, you need to do some work, such as checking that you don't use any freeips based services on the EJBCA container (it doesn't in any way), kerberos is not configured or used, or that EJBCA is java based and openssl is not used. There are other factors when you read the details of CVEs most of the time making them not relevant. So yes unfortunately scans will (almost) always give false positives and it is some work to look at them and mark as not affected. We put them out when we can and …

Replies: 1 comment

Comment options

You must be logged in to vote
0 replies
Answer selected by WilliamM7
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants