Key | Value |
---|---|
Timestamp | 2024-07-05T12:07:05+00:00 |
Signature | unsigned |
Tool |
Vendor: aquasecurity Name: trivy Version: 0.53.0 |
Component |
bom-ref: pkg:oci/jenkins@sha256%3Af2e76ce1ba8d7b357f79a6f174b6696d3ede0cd9c323c5bd7347bf945807ac29?arch=amd64&repository_url=index.docker.io%2Fjenkins%2Fjenkins Type: container Name: jenkins/jenkins purl: pkg:oci/jenkins@sha256%3Af2e76ce1ba8d7b357f79a6f174b6696d3ede0cd9c323c5bd7347bf945807ac29?arch=amd64&repository_url=index.docker.io%2Fjenkins%2Fjenkins Properties:
|
The SSL protocol, as used in certain configurations in Microsoft Windows and Microsoft Internet Expl...
In MIT Kerberos 5 (aka krb5) before 1.21.3, an attacker can cause invalid memory reads during GSS me...
GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may bypass stack guard p...
MiniZip in zlib through 1.3 has an integer overflow and resultant heap-based buffer overflow in zipO...
An issue was discovered in libexpat before 2.6.3. nextScaffoldPart in xmlparse.c can have an integer...
Pivotal Spring Framework through 5.3.16 suffers from a potential remote code execution (RCE) issue i...
Git is a revision control system. Prior to versions 2.45.1, 2.44.1, 2.43.4, 2.42.2, 2.41.1, 2.40.2, ...
Issue summary: Calling the OpenSSL API function SSL_select_next_proto with an empty supported client...
Jenkins 2.470 and earlier, LTS 2.452.3 and earlier allows agent processes to read arbitrary files fr...
Spring WebFlux applications that have Spring Security authorization rules on static resources can be...
An issue was discovered in libexpat before 2.6.3. dtdCopy in xmlparse.c can have an integer overflow...
Issue summary: Some non-default TLS server configurations can cause unbounded memory growth when pro...
XStream is a simple library to serialize objects to XML and back again. This vulnerability may allow...
cipher/elgamal.c in Libgcrypt through 1.8.2, when used to encrypt messages directly, improperly enco...
The Closest Encloser Proof aspect of the DNS protocol (in RFC 5155 when RFC 9276 guidance is skipped...
# | Description | Score | Score Progress |
---|---|---|---|
1 | provided sbom is in a supported sbom format of spdx,cyclonedx | 10.0 |
|
2 | provided sbom should be in supported spec version for spec:1.6 and versions: 1.0,1.1,1.2,1.3,1.4,1.5,1.6 | 10.0 |
|
3 | provided sbom should be in supported file format for spec: json and version: json,xml | 10.0 |
|
4 | provided sbom is parsable | 10.0 |
|
# | Description | Score | Score Progress |
---|---|---|---|
1 | 150/312 have supplier names | 4.8 |
|
2 | 312/312 have names | 10.0 |
|
3 | 311/312 have versions | 10.0 |
|
4 | 312/312 have unique ID's | 10.0 |
|
5 | doc has 161 dependencies | 10.0 |
|
6 | doc has 1 authors | 10.0 |
|
7 | doc has creation timestamp 2024-07-05T12:07:05+00:00 | 10.0 |
|
# | Description | Score | Score Progress |
---|---|---|---|
1 | Doc Fields:true Pkg Fields:true | 10.0 |
|
2 | 143/312 have licenses | 4.6 |
|
3 | 0/312 have checksums | 0.0 |
|
# | Description | Score | Score Progress |
---|---|---|---|
1 | 138/312 components with valid license | 3.3 |
|
2 | 312/312 components have primary purpose specified | 10.0 |
|
3 | 126/312 components have deprecated licenses | 6.0 |
|
4 | 0/312 components have restricted licenses | 10.0 |
|
5 | 311/312 components have any lookup id | 10.0 |
|
6 | 0/312 components have multiple lookup id | 0.0 |
|
7 | 1/1 tools have creator and version | 10.0 |
|
8 | primary component found | 10.0 |
|
# | Description | Score | Score Progress |
---|---|---|---|
1 | doc has a sharable license free 0 :: of 0 | 0.0 |
|