Key | Value |
---|---|
Timestamp | 2024-07-05T12:07:05+00:00 |
Signature | unsigned |
Tool |
Vendor: aquasecurity Name: trivy Version: 0.53.0 |
Component |
bom-ref: pkg:oci/jenkins@sha256%3Af2e76ce1ba8d7b357f79a6f174b6696d3ede0cd9c323c5bd7347bf945807ac29?arch=amd64&repository_url=index.docker.io%2Fjenkins%2Fjenkins Type: container Name: jenkins/jenkins purl: pkg:oci/jenkins@sha256%3Af2e76ce1ba8d7b357f79a6f174b6696d3ede0cd9c323c5bd7347bf945807ac29?arch=amd64&repository_url=index.docker.io%2Fjenkins%2Fjenkins Properties:
|
A vulnerability was found in the Libksba library due to an integer overflow within the CRL parser. T...
# Pivotal Spring Framework contains unsafe Java deserialization methods Pivotal Spring Framework bef...
# Spring Security vulnerable to Authorization Bypass of Static Resources in WebFlux Applications Spr...
# Summary Git is a revision control system. Prior to versions 2.45.1, 2.44.1, 2.43.4, 2.42.2, 2.41.1...
A vulnerability in pam_modules of SUSE Linux Enterprise allows attackers to log into accounts that s...
# Summary When curl retrieves an HTTP response, it stores the incoming headers so that they can be a...
wall in util-linux through 2.40, often installed with setgid tty permissions, allows escape sequence...
# Summary cipher/elgamal.c in Libgcrypt through 1.8.2, when used to encrypt messages directly, impro...
...
libcurl's ASN1 parser has this utf8asn1str() function used for parsing an ASN.1 UTF-8 string. Itcan ...
# Jenkins Remoting library arbitrary file read vulnerability Jenkins uses the Remoting library (typi...
# Summary Git is a revision control system. Prior to versions 2.30.9, 2.31.8, 2.32.7, 2.33.8, 2.34.8...
When curl retrieves an HTTP response, it stores the incoming headers so that they can be accessed la...
Git is a distributed revision control system with a decentralized architecture. As opposed to centra...
libexpat through 2.6.1 allows an XML Entity Expansion attack when there is isolated use of external ...
# | Description | Score | Score Progress |
---|---|---|---|
1 | provided sbom is in a supported sbom format of spdx,cyclonedx | 10.0 |
|
2 | provided sbom should be in supported spec version for spec:1.6 and versions: 1.0,1.1,1.2,1.3,1.4,1.5,1.6 | 10.0 |
|
3 | provided sbom should be in supported file format for spec: json and version: json,xml | 10.0 |
|
4 | provided sbom is parsable | 10.0 |
|
# | Description | Score | Score Progress |
---|---|---|---|
1 | 150/312 have supplier names | 4.8 |
|
2 | 312/312 have names | 10.0 |
|
3 | 311/312 have versions | 10.0 |
|
4 | 312/312 have unique ID's | 10.0 |
|
5 | doc has 161 dependencies | 10.0 |
|
6 | doc has 1 authors | 10.0 |
|
7 | doc has creation timestamp 2024-07-05T12:07:05+00:00 | 10.0 |
|
# | Description | Score | Score Progress |
---|---|---|---|
1 | Doc Fields:true Pkg Fields:true | 10.0 |
|
2 | 143/312 have licenses | 4.6 |
|
3 | 0/312 have checksums | 0.0 |
|
# | Description | Score | Score Progress |
---|---|---|---|
1 | 138/312 components with valid license | 3.3 |
|
2 | 312/312 components have primary purpose specified | 10.0 |
|
3 | 126/312 components have deprecated licenses | 6.0 |
|
4 | 0/312 components have restricted licenses | 10.0 |
|
5 | 311/312 components have any lookup id | 10.0 |
|
6 | 0/312 components have multiple lookup id | 0.0 |
|
7 | 1/1 tools have creator and version | 10.0 |
|
8 | primary component found | 10.0 |
|
# | Description | Score | Score Progress |
---|---|---|---|
1 | doc has a sharable license free 0 :: of 0 | 0.0 |
|