Back to News
Advertisement
Advertisement

⚡ Community Insights

Discussion Sentiment

100% Positive

Analyzed from 231 words in the discussion.

Trending Topics

#deb#cves#unique#curl#pretty#base#image#unhardened#packages#linux

Discussion (10 Comments)Read Original on HackerNews

halestockabout 1 hour ago
Pretty impressive to introduce 1400 CVEs in a project that's only ~7 months old.
GavCoabout 1 hour ago
These are CVEs in the base image and in standard lib dependencies. For example, just scanned an unhardened image I built today:

  Unhardened: docker.io/nanoco/nanoclaw:agent-alpha
  71 packages, 344 unique CVEs, linux/arm64

  PACKAGE         VERSION        TYP   C   H   M   L   N  TOT
  -----------------------------------------------------------
  expat           2.5.0          deb   0   4  18   1   2   25
  curl            7.88.1         deb   4   4   6   0   7   21
  hono            4.12.14        npm   0   1  18   2   0   21
  libtiff         4.5.0          deb   0   2   1   1  15   20
  perl            5.36.0         deb   5   6   3   0   3   17
  pnpm            10.33.0        npm   0   8   7   0   0   15
  glibc           2.36           deb   1   2   2   1   7   13
  openjpeg        2.5.0          deb   0   0   3   1   9   13
  cups            2.4.2          deb   0   2   8   0   1   11
  glib2           2.74.6         deb   1   7   1   0   1   10
  tar             1.34(+2)       deb   1   1   7   0   1   10
  llvm            15.0.6         deb   0   0   0   1   9   10
  sqlite3         3.40.1         deb   1   2   3   0   3    9
  nss             3.87.1         deb   1   0   3   0   4    8
  avahi           0.8            deb   0   0   8   0   0    8
  util-linux      2.38.1         deb   0   0   3   0   2    7
  elf             0.188          deb   0   0   0   0   7    7
  libssh2         1.10.0         deb   1   4   1   0   0    6
  openldap        2.5.13         deb   0   1   0   0   5    6
  chromium        151.0.7922.108 deb   0   5   0   0   0    5
  -----------------------------------------------------------
  UNIQUE CVEs                         16  68 121  17 119  344

  (+51 more packages, 102 findings)

  C/H/M/L/N = critical/high/medium/low/negligible.
  Counts are unique CVEs: binaries from one source package are
  grouped (libcurl4 + libcurl3-gnutls + curl = curl), so a CVE
  hitting three of them counts once, not three times.
devinabout 1 hour ago
If the thing measuring whether there are CVEs is also the thing creating said CVEs, are we sure they are even CVEs? Deduped? Etc.
random319 minutes ago
It’s like it’s made of CVEs. First 50-100 should be a good sign if it’s cleaner to start over.
evanjrowley13 minutes ago
Why is the Node ecosystem like this? Why do people continue to choose it for popular projects vs. anything else?
aliasxneoabout 1 hour ago
I'm convinced you can tackle 5-10 "CVEs" a day, make a little dashboard, put some pretty graphs on it, and send it to your exec team and probably get accolades. Nevermind that the CVEs had nothing to do with your product.
nathancahill44 minutes ago
This is how Vanta et al. make millions.
iandanforthabout 1 hour ago
I don't understand the 'custom patch' strategy over 'fix the app with a major version change' strategy.
KaiserProabout 2 hours ago
so s/bookworm/trixie/g didn't work then?

Yes, this is mostly a joke, I am able to understand the difference between base distros.

iririririr9 minutes ago
a spot on "joke". deb12 is gone for a month now.