UNCLASSIFIED - NO CUI

chore(findings): collaborationai/crowd-vector/stylepack

Summary

collaborationai/crowd-vector/stylepack has 10 new findings discovered during continuous monitoring.

id source package
GHSA-hj48-42vr-x3v9 anchore_cve path-parse-1.0.6
GHSA-hj48-42vr-x3v9 anchore_cve path-parse-1.0.6
GHSA-3jfq-g458-7qm9 anchore_cve tar-4.4.13
GHSA-r628-mhmh-qjhw anchore_cve tar-4.4.13
GHSA-3jfq-g458-7qm9 anchore_cve tar-6.1.0
GHSA-r628-mhmh-qjhw anchore_cve tar-6.1.0
CVE-2021-32803 twistlock_cve tar-4.4.13
CVE-2021-32804 twistlock_cve tar-4.4.13
CVE-2021-32803 twistlock_cve tar-6.1.0
CVE-2021-32804 twistlock_cve tar-6.1.0

More information can be found in the failed pipeline located here: https://repo1.dso.mil/dsop/collaborationai/crowd-vector/stylepack/-/jobs/5628190

Definition of Done

Justifications:

  • All findings have been justified
  • Justifications have been provided to the container hardening team

Approval Process:

  • Findings Approver has reviewed and approved all justifications
  • Approval request has been sent to Authorizing Official
  • Approval request has been processed by Authorizing Official