Skip to content

Refine CVE check in scs-0210-v2 test script. #526

@mbuechse

Description

@mbuechse

The test script currently does not really check whether any patch-level update that targets any critical CVEs is deployed in time.

Furthermore, the standard is a bit vague about whether this part is actually required or recommended.

Thirdly, could you make some kind of suggestion of how to best integrate with CVE check tools? For instance, the test script could accept a log file by one of these tools and just verify that the tool ran fine. You could then add this to the standard as a recommendation; I think we might get this in even with the now stable standard because it wouldn't turn any compliant clouds non-compliant.

Metadata

Metadata

Assignees

Labels

ContainerIssues or pull requests relevant for Team 2: Container Infra and ToolingSCS is standardizedSCS is standardizedSCS-VP10Related to tender lot SCS-VP10

Type

No type

Projects

Status

Backlog

Relationships

None yet

Development

No branches or pull requests

Issue actions