UNCLASSIFIED - NO CUI

chore(findings): opensource/jupyterhub/configurable-http-proxy

Summary

opensource/jupyterhub/configurable-http-proxy has 3 new findings discovered during continuous monitoring.

id source package
CVE-2021-29060 anchore_cve color-string-1.5.4
GHSA-257v-vj4p-3w2h anchore_cve color-string-1.5.4
CVE-2021-29060 twistlock_cve color-string-1.5.4

More information can be found in the failed pipeline located here: https://repo1.dso.mil/dsop/opensource/jupyter/jupyterhub-configurable-http-proxy/-/jobs/4605726

Definition of Done

Justifications:

  • All findings have been justified
  • Justifications have been provided to the container hardening team

Approval Process:

  • Findings Approver has reviewed and approved all justifications
  • Approval request has been sent to Authorizing Official
  • Approval request has been processed by Authorizing Official
Edited by John Stacy