# Liquibase vulnerability scan

**URL:** <https://forum.liquibase.org/t/liquibase-vulnerability-scan/4315>\
**Category:** General Discussion\
**Created:** [June 12, 2020, 5:33am UTC](https://forum.liquibase.org/t/liquibase-vulnerability-scan/4315 "2020-06-12T05:33:15Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Danny](https://avatars.discourse-cdn.com/v4/letter/d/848f3c/32.png) [@Danny](https://forum.liquibase.org/u/Danny)\
**Post date:** [June 12, 2020, 5:33am UTC](https://forum.liquibase.org/t/liquibase-vulnerability-scan/4315/1 "2020-06-12T05:33:16Z")

</div>

Hi,

Has Liquibase a reference to continuous vulnerability scans?  
Any known vulnerabilities in version 3.5.3?

In addition, we are required to run security scans on our repositories. Is anyone aware how can Liquibase SQL output be scanned? Is there a tool that can scan that for security issues?

Regards,  
Daniel

---

<div class="post-metadata">

**Author:** ![ronak](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.liquibase.org/ronak/32/221_2.png) [@ronak](https://forum.liquibase.org/u/ronak)\
**Post date:** [July 1, 2020, 6:33pm UTC](https://forum.liquibase.org/t/liquibase-vulnerability-scan/4315/2 "2020-07-01T18:33:52Z")

</div>

Hi @Danny!

Let me see if I can track that info. I want to know too! We just changed up parts of our release process so I will check and get back to you.

-Ronak

---

<div class="post-metadata">

**Author:** ![ronak](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.liquibase.org/ronak/32/221_2.png) [@ronak](https://forum.liquibase.org/u/ronak)\
**Post date:** [July 1, 2020, 7:10pm UTC](https://forum.liquibase.org/t/liquibase-vulnerability-scan/4315/3 "2020-07-01T19:10:18Z")

</div>

Hello again @Danny,

I just spoke with @NathanVoxland and I’ll just quote him:

> We don’t have security scan information back to 3.5.3. For current versions of liquibase, we have two tools we use:
> 
> 1. SonarCloud’s vulnerability scanning, which you can see the results for at [SonarCloud](https://sonarcloud.io/project/issues?id=liquibase_liquibase&resolved=false&severities=BLOCKER&types=VULNERABILITY)
> 2. [Snyk.io](http://snyk.io/) which outputs a report we are not licensed to share currently
> 
> Sonarcloud does list vulnerabilities we are going to address, but both are based on the attacker putting specific XML into your changelog file, and if an attacker can put arbitrary XML into your changelog file you are going to have larger problems than the vulnerability they list.The Snyk report is not finding any vulnerabilities

Please let me know if you have any questions.

-Ronak

---

<div class="post-metadata">

**Author:** ![Danny](https://avatars.discourse-cdn.com/v4/letter/d/848f3c/32.png) [@Danny](https://forum.liquibase.org/u/Danny)\
**Post date:** [July 2, 2020, 4:55am UTC](https://forum.liquibase.org/t/liquibase-vulnerability-scan/4315/4 "2020-07-02T04:55:13Z")

</div>

Hi @ronak!

Thanks for this valuable info.  
We will check this options for our process.

Best!  
Daniel
