UNCLASSIFIED - NO CUI

chore(findings): ruby27

Summary

Container has new findings discovered during continuous monitoring.

ERROR: The following vulnerabilities are not whitelisted:
ERROR: scan_source                   cve_id                        package                       package_path                  
ERROR: anchore_cve                   GHSA-fp4w-jxhp-m23p           bundler-2.1.4                 /usr/local/lib/ruby/gems/2.7.0/specifications/default/bundler-2.1.4.gemspec    
ERROR: twistlock_cve                 CVE-2020-36327                bundler-2.1.4                 None                          

Definition of Done

Justifications:

  • All findings have been justified
  • Justifications have been provided to the container hardening team

Approval Process:

  • Findings Approver has reviewed and approved all justifications
  • Approval request has been sent to Authorizing Official
  • Approval request has been processed by Authorizing Official

/cc @ironbank-notifications/security

Edited by Andy Maksymowicz