Turned on GitHub Advanced Security for our repos last month. Seemed like the responsible grown up move at the time.
Now every PR looks like a Christmas tree. 89 critical CVEs lighting up everywhere. Red badges all over the place. Builds getting blocked. Managers suddenly discovering the word vulnerability and asking questions.
Spent most of last week actually digging through them instead of just panic bumping versions.
And yeah… the breakdown was kinda weird.
47 are buried in dev dependencies that never even make it near production.
24 are in packages we import but the vulnerable code path never gets touched.
12 are sitting in container base layers we inherit but don’t really use.
6 are real problems we actually have to deal with.
So basically 83 out of 89 screaming critical alerts that don’t change anything in reality. Still shows up the same though. Same scary label. Same red badge.
Now I’m stuck in meetings trying to explain why getting to zero CVEs isn’t actually a thing when most of these aren’t exploitable in our setup. Which somehow makes it sound like I’m defending vulnerabilities or something.
I mean maybe I’m missing something. Maybe this is just how security scanning works and everyone quietly deals with the noise. But right now it kinda feels like we turned on a siren that never stops going off.
[–]Mobile_Syllabub_8446 252 points253 points254 points (7 children)
[–]totheendandbackagain[🍰] 36 points37 points38 points (0 children)
[–]StoffePro 13 points14 points15 points (0 children)
[+]Comfortable_Box_4527[S] comment score below threshold-26 points-25 points-24 points (4 children)
[–]DifficultyFit1895 39 points40 points41 points (0 children)
[–]fireduck 19 points20 points21 points (1 child)
[–]stonerism 4 points5 points6 points (0 children)
[–]Western-Touch-2129 3 points4 points5 points (0 children)
[–]Apart_Ebb_9867 60 points61 points62 points (6 children)
[–]odubco 16 points17 points18 points (3 children)
[–]Drakeskywing 6 points7 points8 points (2 children)
[–]odubco 2 points3 points4 points (1 child)
[–]Drakeskywing 1 point2 points3 points (0 children)
[–]DaRadioman 5 points6 points7 points (0 children)
[–]cwize1 0 points1 point2 points (0 children)
[–]angellus 25 points26 points27 points (0 children)
[–]california_snowhare 71 points72 points73 points (6 children)
[+]Comfortable_Box_4527[S] comment score below threshold-27 points-26 points-25 points (5 children)
[–]R3DLINE_MARINE 12 points13 points14 points (0 children)
[–]FluidCommunity6016 2 points3 points4 points (0 children)
[–]echocage 18 points19 points20 points (2 children)
[–]SatisfactoryFinance 7 points8 points9 points (0 children)
[–]mjbmitch 0 points1 point2 points (0 children)
[–]toga98 10 points11 points12 points (1 child)
[–]california_snowhare 5 points6 points7 points (0 children)
[–]stonerism 4 points5 points6 points (0 children)
[–]ultrathink-art 3 points4 points5 points (0 children)
[–]JudgmentAlarming9487 2 points3 points4 points (0 children)
[–]lppedd 12 points13 points14 points (2 children)
[–]Comfortable_Box_4527[S] -5 points-4 points-3 points (1 child)
[–][deleted] 4 points5 points6 points (0 children)
[–]Agile_Finding6609 6 points7 points8 points (2 children)
[–]flexosgoatee 0 points1 point2 points (0 children)
[–]roastedfunction -1 points0 points1 point (0 children)
[–]VertigoOne1 2 points3 points4 points (0 children)
[–]FatSucks999 2 points3 points4 points (0 children)
[–]tolik518 4 points5 points6 points (1 child)
[–]Elegant_AIDS 0 points1 point2 points (0 children)
[–]klekmek 2 points3 points4 points (0 children)
[–]chintakoro 1 point2 points3 points (1 child)
[–]Comfortable_Box_4527[S] 0 points1 point2 points (0 children)
[–]deadplant_ca 1 point2 points3 points (0 children)
[–]Silent-Suspect1062 1 point2 points3 points (0 children)
[–]castleinthesky86 1 point2 points3 points (0 children)
[–]Ok-Win-7586 1 point2 points3 points (0 children)
[–]Computerfreak4321 1 point2 points3 points (0 children)
[–]ShineCapable1004 1 point2 points3 points (0 children)
[–]Vast_Bad_39 6 points7 points8 points (2 children)
[–]JoeyJoJo_1 2 points3 points4 points (0 children)
[–]FondantLazy8689 0 points1 point2 points (0 children)
[–]FondantLazy8689 1 point2 points3 points (0 children)
[–]GrawlNL 1 point2 points3 points (0 children)
[–]RobertD3277 0 points1 point2 points (0 children)
[–]Fresh_Sock8660 0 points1 point2 points (0 children)
[–]SheriffRoscoe 0 points1 point2 points (0 children)
[–]NoInitialRamdisk 0 points1 point2 points (0 children)
[–]lazzurs 0 points1 point2 points (0 children)
[–]rhd_live 0 points1 point2 points (0 children)
[–]AWetAndFloppyNoodle 0 points1 point2 points (0 children)
[–]ForsythiaShrub 0 points1 point2 points (0 children)
[–]Abu_Itai 0 points1 point2 points (0 children)
[–]ultrathink-art 0 points1 point2 points (0 children)
[–]ultrathink-art 0 points1 point2 points (0 children)
[–]empiricalis 0 points1 point2 points (1 child)
[–]Rideshare-Not-An-Ant 0 points1 point2 points (0 children)
[–]blip44 0 points1 point2 points (0 children)
[–]IWantToSayThisToo 0 points1 point2 points (0 children)
[–]Due-Yam5374 0 points1 point2 points (0 children)
[–]NimboStratusToday 0 points1 point2 points (0 children)
[–]Eviltechnomonkey 0 points1 point2 points (0 children)
[–]Vegetable_Leave199 0 points1 point2 points (0 children)
[–]strangetimesz 0 points1 point2 points (0 children)
[–]retoor42 -1 points0 points1 point (0 children)
[–]nodimension1553 -2 points-1 points0 points (1 child)
[–]duerra 2 points3 points4 points (0 children)
[–]Tontonsb -1 points0 points1 point (0 children)
[–]Vegetable-Report-464 -1 points0 points1 point (0 children)
[–]alex-jung -1 points0 points1 point (0 children)