-
Notifications
You must be signed in to change notification settings - Fork 26
Open
Labels
ContainerIssues or pull requests relevant for Team 2: Container Infra and ToolingIssues or pull requests relevant for Team 2: Container Infra and ToolingSCS is standardizedSCS is standardizedSCS is standardizedSCS-VP10Related to tender lot SCS-VP10Related to tender lot SCS-VP10
Milestone
Description
The test script currently does not really check whether any patch-level update that targets any critical CVEs is deployed in time.
Furthermore, the standard is a bit vague about whether this part is actually required or recommended.
Thirdly, could you make some kind of suggestion of how to best integrate with CVE check tools? For instance, the test script could accept a log file by one of these tools and just verify that the tool ran fine. You could then add this to the standard as a recommendation; I think we might get this in even with the now stable standard because it wouldn't turn any compliant clouds non-compliant.
Metadata
Metadata
Assignees
Labels
ContainerIssues or pull requests relevant for Team 2: Container Infra and ToolingIssues or pull requests relevant for Team 2: Container Infra and ToolingSCS is standardizedSCS is standardizedSCS is standardizedSCS-VP10Related to tender lot SCS-VP10Related to tender lot SCS-VP10
Type
Projects
Status
Backlog