Investigate using clair unstable master branch for CVSSv3 support

As discussed in the following comment, the current container scanning tool uses clair-scanner v2.0.8 (which also runs clair server v2.0.8).

The new container scanning tool implemented in gitlab-org/security-products/analyzers/klar!1 (merged) uses the current stable clair v2.0.9 branch. Both clair v2.0.8 and v2.0.9 will only report CVSSv2 data, meanwhile, the unstable git master branch does provide CVSSv3 data.

The purpose of this issue is to investigate updating the clair server in https://gitlab.com/gitlab-org/security-products/analyzers/klar/ to the unstable git master branch to provide CVSSv3 data

Edited Sep 10, 2019 by Adam Cohen
Assignee Loading
Time tracking Loading