Uploaded image for project: 'IT: Release Engineering'
  1. IT: Release Engineering
  2. RELENG-2046

List all insecure plugins on all jenkins

Issue XMLXMLWordPrintable

    • Icon: Story Story
    • Resolution: Won't Do
    • Icon: Normal Normal
    • None
    • None
    • None

      lftools jenkins -s 'build.opnfv.org/ci' plugins sec

      now lists any vulnerable plugins:

      example:
      $ lftools jenkins -s 'build.opnfv.org/ci' plugins sec
      Jenkins Updates shows a vulnerability in pam-auth 1.5 https://jenkins.io/security/advisory/2019-05-21/#SECURITY-1316
      We are Running pam-auth 1.5
      Jenkins Updates shows a vulnerability in credentials 2.1.18 https://jenkins.io/security/advisory/2019-05-21/#SECURITY-1322
      We are Running credentials 2.1.18

      Next is too have the job run daily on the internal jenkins server and email the relevant RE's

              agardner Aric Gardner
              agardner Aric Gardner
              Votes:
              0 Vote for this issue
              Watchers:
              1 Start watching this issue

                Created:
                Updated:
                Resolved: