Home / Companies / GitLab / Blog / Post Details
Content Deep Dive

Bug found and resolved in Dependency Scanning

Blog post from GitLab

Post Details
Company
Date Published
Author
Nicole Schwartz
Word Count
381
Company Posts That Month
24
Language
English
Hacker News Points
-
Post removed?
No
Summary

GitLab's Dependency Scanning tool, which uses the GitLab Vulnerability Database for the latest advisory data, experienced a bug affecting versions between v2.8.1 and v2.28.0 of the gemnasium analyzer, resulting in outdated scan results as the vulnerability database was not updating at scan time. This issue impacted advisories identified only up to the release date of the analyzer image, potentially leaving users with outdated security information for several weeks. While most customers will automatically receive a fix and update to the latest advisory database, users with customized setups or specific pull policies may need to manually update their docker images to a non-affected version. The specific analyzers affected include gemnasium, gemnasium-python, and gemnasium-maven, with updates required to versions v2.28.1, v2.17.3, and v2.20.4, respectively, to ensure that Dependency Scanning jobs are synchronized with the most recent advisories.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.