이 콘텐츠는 선택한 언어로 제공되지 않습니다.

Chapter 3. Bug fixes


In this release of Red Hat Trusted Profile Analyzer (RHTPA), we fixed the following bugs. In addition to these fixes, we list the descriptions of previously known issues found in earlier versions that we fixed.

The bombastic-collector does not handle special characters in the id field

Before this update, uploading a software bill of materials (SBOM) file that contains special characters in the id field fails to ingest properly when running RHTPA on Amazon Web Services (AWS) infrastructure. This was causing missing data on the vulnerabilities page. With this release, you can now use special characters in the id field before uploading the SBOM.

The collector-osv fails to ingest vulnerabilities with a CVSS_V4 severity

Before this update, vulnerability data available from the OpenSource Vulnerability (OSV) service fails to associate vulnerabilities with a CVSS_V4 score to the packages that they impact. Because of this, fewer vulnerabilities might be associated to packages and software bill of materials (SBOM) that have been ingested into RHTPA. With this release, this issue has been fixed.

Fixed a potential exploit for CVE-2024-21536

With this release, we updated the http-proxy-middleware component in RHTPA to a version that mitigates the vulnerability for CVE-2024-21536.

The v11y-walker job fails when ingesting CVEs

The v11y-walker job would generate an error when the prefix configuration to ingest Common Vulnerabilities and Exposures (CVE) was not applied properly. The prefix configuration determines the range of CVEs to ingest. Because of the wrong range, this caused RHTPA to ingest unwanted CVEs. With this release, we fixed the CVE ingestion process to only match CVEs that use the supplied prefix configuration.

Fixed a potential exploit for CVE-2024-21538

With this release, we updated the cross-spawn component in RHTPA to a version that mitigates the vulnerability for CVE-2024-21538.

A timeout error occurs when doing an SBOM bulk upload

When doing a software bill of materials (SBOM) bulk upload, this causes the SBOM dashboard to fail when loading, giving a connection timeout error. With this release, we fixed the livenessProbe to use curl to connect to the appropriate endpoint.

The initialDelaySeconds property for livenessProbe and readinessProbe are configurable

Before this update, we had a hard-coded value of 2 seconds set on the initialDelaySeconds property for livenessProbe and readinessProbe. With this release, you can configure the initialDelaySeconds property in the RHTPA Helm values file.

A partially ingested SBOM gives an error on the Vulnerabilities tab

Uploading a software bill of materials (SBOM) file has many steps to complete during the ingesting process. Until this ingestion process finishes, viewing SBOM vulnerability information is inconsistent, and the page could display an error message, when no real error occurred. With this release, we removed this error message, and return an empty page on the Vulnerabilities tab.

The guac-collectsub-pod-service pod is caught in an infinite restart loop

Deploying RHTPA on Red Hat Enterprise Linux by using the Ansible Playbook would cause the health check to fail on the guac-collectsub-pod-service pod. This caused the pod to enter an infinite restart loop. With this release, we fixed the livenessProbe by enabling the correct API endpoint.

Fixed a timeout issue when ingesting SBOMs for the dashboard charts

When ingesting a software bill of materials (SBOM) file that has a large number of packages, and if those packages have many associated vulnerabilities, then the API call to retrieve the data for the dashboard charts would timeout. With this release, we made improvements to the API calls that give data to the dashboard charts, therefore populating the dashboard charts properly and in a timely manner.

Missing CVSS scores for some CVEs

Some Common Vulnerabilities and Exposures (CVE) have elements in the metrics array, but have no corresponding Common Vulnerability Scoring System (CVSS) score. Not having the CVSS score limits the ability to query for data on CVEs. With this release, we do a check for a valid CVSS score within the elements in the metrics array, and properly display the CVE’s CVSS score.

Nested packages within a CycloneDX SBOM are not ingested

We fixed a bug where only the main package gets ingested, but the nested packages do not. With this release, RHTPA correctly traverses a CycloneDX software bill of materials (SBOM) manifest file, and includes those nested packages in the database.

Large SBOM manifest files generate an error when uploading

When uploading a large software bill of materials (SBOM) manifest file to RHTPA, the index updates properly, but the database does not. We consider a large SBOM manifest file to be 90 MB in size, containing 70,000 packages. With this release, we fixed the issue with the database update.

맨 위로 이동
Red Hat logoGithubredditYoutubeTwitter

자세한 정보

평가판, 구매 및 판매

커뮤니티

Red Hat 문서 정보

Red Hat을 사용하는 고객은 신뢰할 수 있는 콘텐츠가 포함된 제품과 서비스를 통해 혁신하고 목표를 달성할 수 있습니다. 최신 업데이트를 확인하세요.

보다 포괄적 수용을 위한 오픈 소스 용어 교체

Red Hat은 코드, 문서, 웹 속성에서 문제가 있는 언어를 교체하기 위해 최선을 다하고 있습니다. 자세한 내용은 다음을 참조하세요.Red Hat 블로그.

Red Hat 소개

Red Hat은 기업이 핵심 데이터 센터에서 네트워크 에지에 이르기까지 플랫폼과 환경 전반에서 더 쉽게 작업할 수 있도록 강화된 솔루션을 제공합니다.

Theme

© 2026 Red Hat