We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
1 parent 5de5ceb commit e7e5ce5Copy full SHA for e7e5ce5
data/reports/GO-2022-1180.yaml
@@ -3,7 +3,7 @@ modules:
3
versions:
4
- introduced: 1.8.3
5
fixed: 1.8.5
6
- vulnerable_at: 1.8.4
+ vulnerable_at: 1.8.5-0.20221217180442-ef63302dc479
7
packages:
8
- package: github.com/kyverno/kyverno/pkg/engine
9
symbols:
@@ -12,6 +12,7 @@ modules:
12
- imageVerifier.verifyAttestors
13
- imageVerifier.verifyAttestorSet
14
- imageVerifier.verifyImage
15
+ skip_fix: 'TODO: revisit this reason (undefined: gojmespath.NotFoundError)'
16
description: |
17
`verifyImages` rules can be bypassed by a malicious proxy/registry.
18
cves:
0 commit comments