Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update Dependencies to resolve known CVEs #257

Open
wSedlacek opened this issue Nov 7, 2024 · 0 comments
Open

Update Dependencies to resolve known CVEs #257

wSedlacek opened this issue Nov 7, 2024 · 0 comments
Labels
bug Something isn't working

Comments

@wSedlacek
Copy link

wSedlacek commented Nov 7, 2024

Describe the bug
There are several known CVEs found within the dependencies of the stable image.
Image
https://quay.io/repository/mittwald/kube-httpcache/manifest/sha256:ed153b482be398b8d979cf4983b1936a97ca734837aac588e4e5e2f3fca58cbe?tab=vulnerabilities&fixable=true

To Reproduce
Use Docker Scout or a similar CVE scanner to check the stable image.

Expected behavior
It's not entirely unreasonable for there to be some CVEs found within the dependencies, but since there hasn't been an update to the image in 7 months many of these vulnerabilities are likely very easily fixed with some dependency bumps.

Perhaps dependabot or a similar tool with some CI steps to automate the deployments could help reduce the time cost with updating the images moving forward keeping this project healthier?

@wSedlacek wSedlacek added the bug Something isn't working label Nov 7, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug Something isn't working
Projects
None yet
Development

No branches or pull requests

1 participant