Docker Image scan via synopsys/blackduck #1703
-
Hi all, i am not sure if here is the right place to ask, but i have to try and start somewhere. Thanks in advance |
Beta Was this translation helpful? Give feedback.
Replies: 1 comment 2 replies
-
Hi. Cerbos container is a minimal scratch container and does not contain an OS. It would only contain the statically compiled Cerbos binary and the CA root certificates. I am not familiar with BlackDuck software. If you're looking for the list of dependencies of Cerbos, go to the relevant release tag on the Cerbos GitHub repo and examine the |
Beta Was this translation helpful? Give feedback.
Hi. Cerbos container is a minimal scratch container and does not contain an OS. It would only contain the statically compiled Cerbos binary and the CA root certificates.
I am not familiar with BlackDuck software. If you're looking for the list of dependencies of Cerbos, go to the relevant release tag on the Cerbos GitHub repo and examine the
NOTICE.txt
file. It contains a full list of dependencies and their licences. Here's the one for v0.29.0 which was released today: https://github.com/cerbos/cerbos/blob/v0.29.0/NOTICE.txt