Misconfig ds031 Dockerfile check reports many matches when only one exists #7831
Closed
tstraley
started this conversation in
False Detection
Replies: 1 comment
-
Please see #7828 (comment) |
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
IDs
DS031
Description
As of yesterday, this new misconfig check started firing on our scans. We have Dockerfiles that contain something like:
This DS031 check accurately identifies
passwd
in a COPY declaration and alerts on that. But is also report every other pattern used in the regex, for some reason, despite none of these others being in the Dockerfile:Reproduction Steps
Target
Filesystem
Scanner
Misconfiguration
Target OS
No response
Debug Output
Version
Checklist
-f json
that shows data sources and confirmed that the security advisory in data sources was correctBeta Was this translation helpful? Give feedback.
All reactions