Skip to content

Commit

Permalink
italics->cta
Browse files Browse the repository at this point in the history
  • Loading branch information
pritchyspritch committed Nov 27, 2024
1 parent b7e966b commit e66f7c5
Showing 1 changed file with 2 additions and 1 deletion.
3 changes: 2 additions & 1 deletion docs/policies/vulnerability_management_policy.md
Original file line number Diff line number Diff line change
Expand Up @@ -95,7 +95,8 @@ Your vulnerability management process for container images:
#### Upstream base image vulnerabilities
It is a known issue that some common base images have vulnerabilities that can only be fixed by the upstream maintainers.

It is *not* considered an appropriate exception to not patch vulnerabilities in container images because of upstream problems.
??? warning "It is not considered an appropriate exception to not patch vulnerabilities in container images because of upstream problems."
Please work with CISD and your architects to ensure secure base images are used, either by finding appropriate secure base images, by building your own images or other means such as muiti-stage docker builds

To ensure that vulnerabilities in container images are patched within appropriate timescales teams must either:

Expand Down

0 comments on commit e66f7c5

Please sign in to comment.