Package Search Help

You can use boolean logic (e.g. AND/OR/NOT) for complex search queries. For more help and examples, see the search documentation.

Search by package name:
my-package (implicit)
name:my-package (explicit)

Search by package filename:
filename:my-package.ext 

Search by package tag:
tag:latest 

Search by package version:
version:1.0.0  prerelease:true (prereleases)
prerelease:false (no prereleases)

Search by package architecture:
architecture:x86_64 

Search by package distribution:
distribution:el 

Search by package license:
license:MIT 

Search by package format:
format:deb 

Search by package status:
status:in_progress 

Search by package file checksum:
checksum:5afba 

Search by package security status:
severity:critical 

Search by package vulnerabilities:
vulnerabilities:>1 
vulnerabilities:<1000 

Search by # of package downloads:
downloads:>8 
downloads:<100 

Search by package type:
type:binary 
type:source 

Search by package size (bytes):
size:>50000 
size:<10000 

Search by dependency name/version:
dependency:log4j 
dependency:log4j=1.0.0 
dependency:log4j>1.0.0 

Search by uploaded date:
uploaded:>"1 day ago" 
uploaded:<"August 14, 2022 EST" 

Search by entitlement token (identifier):
entitlement:3lKPVJPosCsY 

Search by policy violation:
policy_violated:true
deny_policy_violated:true
license_policy_violated:true
vulnerability_policy_violated:true

Search by repository:
repository:repo-name

Search queries for all Debian-specific (and related) package types

Search by component:
deb_component:unstable

Search queries for all Maven-specific (and related) package types

Search by group ID:
maven_group_id:org.apache

Search queries for all Docker-specific (and related) package types

Search by image digest:
docker_image_digest:sha256:7c5..6d4
(full hashref only)

Search by layer digest:
docker_layer_digest:sha256:4c4..ae4
(full hashref only)

Field type modifiers (depending on the type, you can influence behaviour)

For all queries, you can use:
~foo for negation

For string queries, you can use:
^foo to anchor to start of term
foo$ to anchor to end of term
foo*bar for fuzzy matching

For number/date or version queries, you can use:
>foo for values greater than
>=foo for values greater / equal
<foo for values less than
<=foo for values less / equal

Need a secure and centralised artifact repository to deliver Alpine, Cargo, CocoaPods, Composer, Conan, Conda, CRAN, Dart, Debian, Docker, Go, Helm, Hex, LuaRocks, Maven, npm, NuGet, P2, Python, RedHat, Ruby, Swift, Terraform, Vagrant, Raw & More packages?

Cloudsmith is the new standard in Package / Artifact Management and Software Distribution.

With support for all major package formats, you can trust us to manage your software supply chain.

Start My Free Trial
 Public myob myob / appsec
public appsec packages

Docker logo sonar-scanner  7115904281b236e361cfd3e0b8c…

One-liner (summary)

A certifiably-awesome package curated by ops-arch bot, hosted by Cloudsmith.

Description

A certifiably-awesome package curated by ops-arch bot, hosted by Cloudsmith.

License

Unknown

Size

204.4 MB

Downloads

12943

Status  Completed
Checksum (MD5) f389fcec3c9172091d4388a4e4c15d2e
Checksum (SHA-1) 5f117b2da024d39fcd700019d42b9c540807e6fb
Checksum (SHA-256) 7115904281b236e361cfd3e0b8cb85f4c8f7dec67cacf91e10ab13d564686543
Checksum (SHA-512) 0789ac952ec00e24c1262ce703369b30ba00bbdb0f41b4143305f818d3d6c328d7…
GPG Signature
GPG Fingerprint b37cb02108d5d7b2c7269a09acf5c48b429db520
Storage Region  Dublin, Ireland
Type  Binary (contains binaries and binary artifacts)
Uploaded At 1 month, 3 weeks ago
Uploaded By ops-arch-bot
Slug Id sonar-scanner-ntbb
Unique Id ZkCut9vFek7P
Version (Raw) 7115904281b236e361cfd3e0b8cb85f4c8f7dec67cacf91e10ab13d564686543
Version (Parsed)
  • Type: Unknown
  docker-specific metadata
Image Digest sha256:7115904281b236e361cfd3e0b8cb85f4c8f7dec67cacf91e10ab13d564686543
Config Digest sha256:e9794cc4891ea56fcd92eeeffd1427f3992b392131b25431b1aef81a8bc6267b
V1 OCI Index Digest sha256:e701ad396b2a16371bf3bedfe97d6ee0c56d36f42e1092cde875cf4b3c40f600
V1 Distribution (Signed) Digest sha256:8b5179c3e5e9c8e629d5ca15adc272b2cb1ef3282af74b3e9138a95e0b106365
V1 OCI Digest sha256:a13682e0c154118466334017dd88e8fdd94419f050137ab477a4df4ab70f0f20
V2 Distribution List Digest sha256:a7249c68db947b801cab437ca29c6c0b10c300206eb250fd4fc7df0a074fa243
V1 Distribution Digest sha256:784d602941b1b9f3dec9dabbdc8333aa048d6aa4bdecafe6c2d55ca8dd05336b
V2 Distribution Digest sha256:7115904281b236e361cfd3e0b8cb85f4c8f7dec67cacf91e10ab13d564686543
  extended metadata
Manifest Type V2 Distribution
Architecture amd64
Config
Created 2025-05-07 05:55:45 UTC
Os linux

This package was uploaded with the following V2 Distribution manifest:

{
   "schemaVersion": 2,
   "mediaType": "application/vnd.docker.distribution.manifest.v2+json",
   "config": {
      "mediaType": "application/vnd.docker.container.image.v1+json",
      "size": 6025,
      "digest": "sha256:ea3b0c2203ad96fa8d0505027a647df1a34b23609baa77fe488171e6c5cf1fd6"
   },
   "layers": [
      {
         "mediaType": "application/vnd.docker.image.rootfs.diff.tar.gzip",
         "size": 3379404,
         "digest": "sha256:3c854c8cbf469fda815b8f6183300c07cfa2fbb5703859ca79aff93ae934961b"
      },
      {
         "mediaType": "application/vnd.docker.image.rootfs.diff.tar.gzip",
         "size": 32,
         "digest": "sha256:4f4fb700ef54461cfa02571ae0db9a0dc1e0cdb5577484a6d75e68dc38e8acc1"
      },
      {
         "mediaType": "application/vnd.docker.image.rootfs.diff.tar.gzip",
         "size": 119888205,
         "digest": "sha256:abe98265d20621af12bd6fb29184dbcc565b6e4962601ebc2588cb9dc3c5b36b"
      },
      {
         "mediaType": "application/vnd.docker.image.rootfs.diff.tar.gzip",
         "size": 723,
         "digest": "sha256:c49a837592579e418683af4151503325beb5cb4b1ca4fc45e1267c6c2483ecce"
      },
      {
         "mediaType": "application/vnd.docker.image.rootfs.diff.tar.gzip",
         "size": 32,
         "digest": "sha256:4f4fb700ef54461cfa02571ae0db9a0dc1e0cdb5577484a6d75e68dc38e8acc1"
      },
      {
         "mediaType": "application/vnd.docker.image.rootfs.diff.tar.gzip",
         "size": 89384835,
         "digest": "sha256:911dda69debdbc09df6fe10bbc0c4a5414c2eb2d251d20bceaed85131ea78dcb"
      },
      {
         "mediaType": "application/vnd.docker.image.rootfs.diff.tar.gzip",
         "size": 1725058,
         "digest": "sha256:58385b5db76cefd1e35f7f0697aa0331337c70e25c470e598fc66ad03cdbd73a"
      },
      {
         "mediaType": "application/vnd.docker.image.rootfs.diff.tar.gzip",
         "size": 1115,
         "digest": "sha256:141b303f6f38fb61b6eb875dd91b8b0177aa7744666e7325d28ebaa5bdbf0c45"
      },
      {
         "mediaType": "application/vnd.docker.image.rootfs.diff.tar.gzip",
         "size": 126,
         "digest": "sha256:e6d3eae474c6fce388e0ad72286f1b6a553d3bb76ca206248886289ccf527647"
      }
   ]
}
Digest: sha256:3c854c8cbf469fda815b8f6183300c07cfa2fbb5703859ca79aff93ae934961b
Command: /bin/sh -c #(nop) ADD file:c44c9bd36ba35cc78fb9396304ea008def9f42a3beef76aa33b2cf1fde1c10b3 in /
3.2 MB
Digest: sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: /bin/sh -c #(nop) CMD ["/bin/sh"]
32 bytes
Digest: sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: LABEL org.opencontainers.image.url=https://github.com/SonarSource/sonar-scanner-cli-docker
32 bytes
Digest: sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: ARG SONAR_SCANNER_HOME=/opt/sonar-scanner
32 bytes
Digest: sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: ARG SONAR_SCANNER_VERSION
32 bytes
Digest: sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: ARG UID=1000
32 bytes
Digest: sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: ARG GID=1000
32 bytes
Digest: sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: ENV JAVA_HOME=/usr/lib/jvm/java-17-openjdk HOME=/tmp XDG_CONFIG_HOME=/tmp SONAR_SCANNER_HOME=/opt/sonar-scanner SONAR_USER_HOME=/opt/sonar-scanner/.sonar PATH=/opt/sonar-scanner/bin:/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin NODE_PATH=/usr/lib/node_modules SRC_PATH=/usr/src LANG=en_US.UTF-8 LC_ALL=en_US.UTF-8
32 bytes
Digest: sha256:4f4fb700ef54461cfa02571ae0db9a0dc1e0cdb5577484a6d75e68dc38e8acc1
Command: WORKDIR /opt
32 bytes
Digest: sha256:abe98265d20621af12bd6fb29184dbcc565b6e4962601ebc2588cb9dc3c5b36b
Command: RUN |4 SONAR_SCANNER_HOME=/opt/sonar-scanner SONAR_SCANNER_VERSION=5.0.1.3006 UID=1000 GID=1000 /bin/sh -c set -eux; addgroup -S -g ${GID} scanner-cli; adduser -S -D -u ${UID} -G scanner-cli scanner-cli; apk add --no-cache --virtual build-dependencies wget unzip gnupg; apk add --no-cache git python3 py-pip bash shellcheck 'nodejs>12' openjdk17-jre curl musl-locales musl-locales-lang; wget -U "scannercli" -q -O /opt/sonar-scanner-cli.zip https://binaries.sonarsource.com/Distribution/sonar-scanner-cli/sonar-scanner-cli-${SONAR_SCANNER_VERSION}.zip; wget -U "scannercli" -q -O /opt/sonar-scanner-cli.zip.asc https://binaries.sonarsource.com/Distribution/sonar-scanner-cli/sonar-scanner-cli-${SONAR_SCANNER_VERSION}.zip.asc; for server in $(shuf -e hkps://keys.openpgp.org hkps://keyserver.ubuntu.com) ; do gpg --batch --keyserver "${server}" --recv-keys 679F1EE92B19609DE816FDE81DB198F93525EC1A && break || : ; done; gpg --verify /opt/sonar-scanner-cli.zip.asc /opt/sonar-scanner-cli.zip; unzip sonar-scanner-cli.zip; rm sonar-scanner-cli.zip sonar-scanner-cli.zip.asc; mv sonar-scanner-${SONAR_SCANNER_VERSION} ${SONAR_SCANNER_HOME}; pip install --no-cache-dir --upgrade pip; pip install --no-cache-dir pylint; apk del --purge build-dependencies; mkdir -p "${SRC_PATH}" "${SONAR_USER_HOME}" "${SONAR_USER_HOME}/cache"; chown -R scanner-cli:scanner-cli "${SONAR_SCANNER_HOME}" "${SRC_PATH}"; chmod -R 777 "${SRC_PATH}" "${SONAR_USER_HOME}"; # buildkit
114.3 MB
Digest: sha256:c49a837592579e418683af4151503325beb5cb4b1ca4fc45e1267c6c2483ecce
Command: COPY bin /usr/bin/ # buildkit
723 bytes
Digest: sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: VOLUME [/tmp/cacerts]
32 bytes
Digest: sha256:4f4fb700ef54461cfa02571ae0db9a0dc1e0cdb5577484a6d75e68dc38e8acc1
Command: WORKDIR /usr/src
32 bytes
Digest: sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: ENTRYPOINT ["/usr/bin/entrypoint.sh"]
32 bytes
Digest: sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: CMD ["sonar-scanner"]
32 bytes
Digest: sha256:911dda69debdbc09df6fe10bbc0c4a5414c2eb2d251d20bceaed85131ea78dcb
Command: RUN /bin/sh -c apk upgrade --no-cache && apk add --no-cache python3 py3-pip # buildkit
85.2 MB
Digest: sha256:58385b5db76cefd1e35f7f0697aa0331337c70e25c470e598fc66ad03cdbd73a
Command: RUN /bin/sh -c pip install requests # buildkit
1.6 MB
Digest: sha256:141b303f6f38fb61b6eb875dd91b8b0177aa7744666e7325d28ebaa5bdbf0c45
Command: COPY wrapper.py /usr/local/bin # buildkit
1.1 KB
Digest: sha256:e6d3eae474c6fce388e0ad72286f1b6a553d3bb76ca206248886289ccf527647
Command: WORKDIR /data
126 bytes
Digest: sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: ENTRYPOINT ["wrapper.py"]
32 bytes
Docker logo
sonar-scanner
0 ops-arch-bot
Docker logo
sonar-scanner
0 ops-arch-bot
Docker logo
sonar-scanner
image amd64 linux
0 ops-arch-bot
Docker logo
sonar-scanner
image amd64 linux
0 ops-arch-bot
Docker logo
sonar-scanner
0 ops-arch-bot
Docker logo
sonar-scanner
0 ops-arch-bot
Docker logo
sonar-scanner
0 ops-arch-bot
Docker logo
sonar-scanner
0 ops-arch-bot
Docker logo
sonar-scanner
0 ops-arch-bot
Docker logo
sonar-scanner
28324 ops-arch-bot
Docker logo
sonar-scanner
image amd64 linux
69205 ops-arch-bot
Docker logo
sonar-scanner
0 ops-arch-bot
Docker logo
sonar-scanner
0 ops-arch-bot
Docker logo
sonar-scanner
1 ops-arch-bot
Docker logo
sonar-scanner
6244 ops-arch-bot
Docker logo
sonar-scanner
12943 ops-arch-bot
Docker logo
sonar-scanner
0 ops-arch-bot
Docker logo
sonar-scanner
0 ops-arch-bot
Docker logo
sonar-scanner
4 ops-arch-bot
Docker logo
sonar-scanner
146438 ops-arch-bot

Last scanned

1 month, 3 weeks ago

Scan result

Vulnerable

Vulnerability count

1

Max. severity

Medium
Target: Java
MEDIUM

CVE-2023-3635: okio: GzipSource class improper exception handling

GzipSource does not handle an exception that might be raised when parsing a malformed gzip buffer. This may lead to denial of service of the Okio client when handling a crafted GZIP archive, by using the GzipSource class.

Package Name: com.squareup.okio:okio
Installed Version: 1.17.2
Fixed Version: 3.4.0, 1.17.6

References: access.redhat.com github.com github.com github.com github.com github.com github.com nvd.nist.gov research.jfrog.com research.jfrog.com www.cve.org
Loading...

These instructions assume you have setup the repository first (or read it).

To pull sonar-scanner @ reference/tag latest:

docker pull docker.myob.com/appsec/sonar-scanner:latest

To refer to this image after pulling in a Dockerfile, specify the following:

FROM docker.myob.com/appsec/sonar-scanner:latest

Note: You should replace latest with an alternative reference to pull, such as: preprod and d61b9f591f1b0bdd8cfcf50ad8a3aea971c302e6.

Top