Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

security: Track Possible Image Vulnerabilities #568

Open
scbizu opened this issue Mar 24, 2022 · 15 comments
Open

security: Track Possible Image Vulnerabilities #568

scbizu opened this issue Mar 24, 2022 · 15 comments
Labels
dependencies Pull requests that update a dependency file

Comments

@scbizu
Copy link
Contributor

scbizu commented Mar 24, 2022

Here will be a long issue track possible image vulnerabilities or CVEs reported by the community or our dependabot .

@scbizu scbizu added the dependencies Pull requests that update a dependency file label Mar 24, 2022
@scbizu
Copy link
Contributor Author

scbizu commented Mar 24, 2022

helm/helm#10717 tracks the containerd containerd CRI plugin: Insecure handling of image volumes issue , will upgrade CM after helm upgrade this dependency.

@scbizu scbizu pinned this issue Mar 24, 2022
@slachiewicz
Copy link

Artifacthub.io shows issues with the base image (busybox) and a few of our deps (etcd, contained, docker)
https://artifacthub.io/packages/helm/chartmuseum/chartmuseum

@Kiran-38
Copy link

Hi @scbizu, any update on the security vulnerability reported with #607 please.

@scbizu
Copy link
Contributor Author

scbizu commented Sep 11, 2022

@Kiran-38 Thank you for the report , The storage PR will deprecate the old etcd dependency :) chartmuseum/storage#649

@Kiran-38
Copy link

@scbizu Thank you for the response. Can we have any date of fix for the etcd, or this fix will be in this version 0.15.0 or later. please let us know.

@Kiran-38
Copy link

Hi,
The chartMuseum binary contains the helm.sh/helm/v3 v3.9.3 library with is flagged as a security risk and need to update to the latest version 3.9.4 or later and above available for resolving the issue.

I see there is a branch dependabot created already to fix this can you merge with the main branch so that I can use it.

@Kiran-38
Copy link

@scbizu Thank you for the quick fix. It means a lot. Keep up the great work.

@Kiran-38
Copy link

Kiran-38 commented Mar 5, 2023

Hi @scbizu, there are few vulnerability found in building chartmuseum. please find below list.

github.com/containerd/containerd-v1.6.3   
helm.sh/helm/v3-v3.9.0   
golang.org/x/net-v0.0.0-20220531201128-c960675eff93   
github.com/emicklei/go-restful-v2.9.5+incompatible   
golang.org/x/text-v0.3.7 

@scbizu
Copy link
Contributor Author

scbizu commented Mar 6, 2023

@Kiran-38 ok , I will check it

@Kiran-38
Copy link

Kiran-38 commented Mar 9, 2023

Thanks for the quick fix, I just wanted to know is there any latest release planned with this fix. As the fix is still in main branch, or if there is any tentative date to be released.

@Kiran-38
Copy link

@cbuto @jdolitsky Can you please update all the current Vulnerability fix in any latest release. As there has been a while, if there is any latest release been planned can you please give any date. That will help alot to users like us.

@scbizu
Copy link
Contributor Author

scbizu commented Dec 31, 2023

#737

@macox
Copy link

macox commented Apr 24, 2024

@cbuto @jdolitsky apologies for the tag, do we know when a new release is planned?
it would be great if we could have any open dependabot PRs containing vulnerability fixes included.

@scbizu
Copy link
Contributor Author

scbizu commented Apr 28, 2024

@macox hi , we already open the automated dependabot PRs , and if you want the new release with these PRs , you can try our canary tag , thank you for your advice , but we do not plan to release new release tag about every vulnerability fix.

@macox
Copy link

macox commented Apr 28, 2024

Thanks for your reply @scbizu, sorry I didn’t mean a release for every vulnerability. I was just wondering if a release was planned and if current open dependabot PRs could be merged and included in it.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
dependencies Pull requests that update a dependency file
Projects
None yet
Development

No branches or pull requests

4 participants