Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Feature: Enhance security of the aissemble-spark baseline image #389

Open
1 task
jocobtt opened this issue Oct 3, 2024 · 0 comments
Open
1 task

Feature: Enhance security of the aissemble-spark baseline image #389

jocobtt opened this issue Oct 3, 2024 · 0 comments
Labels
enhancement New feature or request

Comments

@jocobtt
Copy link

jocobtt commented Oct 3, 2024

Description

The current aissemble-spark Docker image contains approximately 16 critical vulnerabilities as identified by security scans. These vulnerabilities are causing the image to be flagged in cloud environments, necessitating downstream projects to undertake additional remediation efforts.

The base image, apache/spark-py, utilized in aissemble-spark is outdated. To mitigate the identified vulnerabilities and improve overall security posture, we propose migrating to a more actively maintained PySpark base image, such as bitnami/spark.

DOD

  • aissemble-spark image is patched to remove resulting critical CVE vulnerabilities before it is released to downstream projects

Test Strategy/Script

  • Build the aissemble-spark image and ensure there aren't critical CVE vulnerabilities reported when scanned by Trivy image scanner or any similar container scanning tools.

References/Additional Context

N/A

@jocobtt jocobtt added the enhancement New feature or request label Oct 3, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New feature or request
Projects
None yet
Development

No branches or pull requests

1 participant