3
0
Fork 0
Go to file
ag fcede714d2 commit by to_remotes 2023-11-02 13:59:57 +0100 from vmdevac 2023-11-02 13:59:57 +01:00
README.md
bundle-audit-time.txt commit by to_remotes 2023-11-02 13:59:57 +0100 from vmdevac 2023-11-02 13:59:57 +01:00
bundle-audit.json commit by to_remotes 2023-11-02 13:59:57 +0100 from vmdevac 2023-11-02 13:59:57 +01:00
git_tag
report.txt
update-info.txt

README.md

How to read the information of a given Commit

By audit we mean checking for vulnerabilities.

bundle-audit.json: This file contains audit information in JSON format

report.txt: In a text format it is described which vulnerabilities have been detected

update-info.txt: Contains Information as of which date the vulnerabilities database is that has been used to perform the checks.

bundle-audit-time.txt: contains time stamp auf audit in ISO format

git_tag: The tag of the application/image/audit at the time audit

What is being checked and how?

The application being checked is Xalimo Teamplay which is a Rails application provided by a docker image. Basis for the check is the set of used packages (called Gems). These are being tested against a constantantly updated database of know vulnerabilities.