


Artifactory XRAY fails when scanning images containing golang packages due to indexer compression ratio limitations
Artifactory XRAY fails when scanning images containing golang packages due to indexer compression ratio limitations. This issue may lead to vulnerabilities not being discovered, thereby increasing the risk of system attacks. The Artifactory XRAY team is actively working on resolving this issue and expects to release a fix in the next release. Until then, users are advised to be aware of this issue when scanning images with Artifactory XRAY and take additional measures to ensure the security of their systems. PHP editor Apple will continue to pay attention to the progress of this issue and provide readers with relevant updates in a timely manner.
Question content
Recently encountered an XRAY problem when scanning docker images containing golang packages, and intercepted the following errors
TarOpener.DeepArchiveScan) --- Caused by: total bytes limit reached with the following values
I have researched this issue and it is caused by the xray limitation of the index packet compression ratio, which is to prevent zip bomb attacks (https://jfrog.com/help/r/xray-why-am-i -getting-a-total-bytes-limit-reached-error-when-indexing-a-package-in-xray/xray-why-am-i-getting-a-total-bytes-limit-reached-in-xray An error occurred while indexing the package).
I'm always pushing limits. This works for a while, but it seems like every time golang is updated, the size of the zip file gets bigger and bigger.
Has anyone implemented a long-term solution to this problem or has a new idea that doesn't just set the limit to an extreme cap value? I basically have to almost double every time?
Workaround
Golang has inserted the pax-bad-hdr-large.tar.bz2 file into its package, which is a test for zip bomb attacks.
A value of 4600 should resolve this file compression ratio.
The above is the detailed content of Artifactory XRAY fails when scanning images containing golang packages due to indexer compression ratio limitations. For more information, please follow other related articles on the PHP Chinese website!

Hot AI Tools

Undresser.AI Undress
AI-powered app for creating realistic nude photos

AI Clothes Remover
Online AI tool for removing clothes from photos.

Undress AI Tool
Undress images for free

Clothoff.io
AI clothes remover

AI Hentai Generator
Generate AI Hentai for free.

Hot Article

Hot Tools

Notepad++7.3.1
Easy-to-use and free code editor

SublimeText3 Chinese version
Chinese version, very easy to use

Zend Studio 13.0.1
Powerful PHP integrated development environment

Dreamweaver CS6
Visual web development tools

SublimeText3 Mac version
God-level code editing software (SublimeText3)

Hot Topics

This article explains Go's package import mechanisms: named imports (e.g., import "fmt") and blank imports (e.g., import _ "fmt"). Named imports make package contents accessible, while blank imports only execute t

This article explains Beego's NewFlash() function for inter-page data transfer in web applications. It focuses on using NewFlash() to display temporary messages (success, error, warning) between controllers, leveraging the session mechanism. Limita

This article details efficient conversion of MySQL query results into Go struct slices. It emphasizes using database/sql's Scan method for optimal performance, avoiding manual parsing. Best practices for struct field mapping using db tags and robus

This article demonstrates creating mocks and stubs in Go for unit testing. It emphasizes using interfaces, provides examples of mock implementations, and discusses best practices like keeping mocks focused and using assertion libraries. The articl

This article explores Go's custom type constraints for generics. It details how interfaces define minimum type requirements for generic functions, improving type safety and code reusability. The article also discusses limitations and best practices

This article details efficient file writing in Go, comparing os.WriteFile (suitable for small files) with os.OpenFile and buffered writes (optimal for large files). It emphasizes robust error handling, using defer, and checking for specific errors.

The article discusses writing unit tests in Go, covering best practices, mocking techniques, and tools for efficient test management.

This article explores using tracing tools to analyze Go application execution flow. It discusses manual and automatic instrumentation techniques, comparing tools like Jaeger, Zipkin, and OpenTelemetry, and highlighting effective data visualization
