I am trying to install AWX from Dockerhub in the company that I work for and we need to follow a process of vulnerability scan before we can import the docker images on the company. The reports of the scan show a lot of high risk vulnerabilities and the company does not want to import the images (see report attached). Anyways I have 2 questions:
Do you know if Ansible Tower version use the same packages and therefore has the same vulnerabilities?
Is it possible to correct all the high/critical/important vulnerabilities in the reports?
Thanks a lot!
We’ll clear out some base images and re-spin the images… these are just coming from the centos7 base images that we used to build them.
Alternatively you should be able to spin these yourself and pick up the new centos:7 base that will pass a security scan if you don’t feel like waiting on us.