Skip to content
Discussion options

You must be logged in to vote

@manoj-md those are Go library vulnerabilities, RabbitMQ server does not use Go.

I have no idea why they show up on a scan, why do you expect our team to fix them, or what image you are talking about to begin with.

Our team helps maintain the community OCI and it has a Go-based tool called gosu but it is only used in Dockerfile templating as far as I can tell. I have asked its primary maintainers for clues docker-library/rabbitmq#794 but it sounds like you'd have to take a closer look at your scan (it's not reasonable to ask open source maintainers to read your scanner output for you and weed out the false positives).

Please take it from here.

Update

Community OCI maintainers explain that g…

Replies: 1 comment 1 reply

Comment options

You must be logged in to vote
1 reply
@michaelklishin
Comment options

Answer selected by michaelklishin
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
2 participants