Replies: 1 comment 10 replies
-
Strimzi builds on top of various other open-source projects and where possible, tries to update them every release. We do not rebuild all the dependencies from the source. If these vulnerabilities were updated in the source projects, they will likely be addressed in the next Strimzi release (which we expect shortly after Apache Kafka 3.7.0 is released). In the meantime, if you want, you can check the individual projects if they addressed these vulnerabilities and if not, contribute to fixes there. And if they did and the latest Strimzi builds from the main branch do not contain them yet, feel free to open a PR to update them. |
Beta Was this translation helpful? Give feedback.
10 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
hi,
we have found the below CVE for the kafka image. can we fix this by updating the docker file? please guide me how to fix this ?
Beta Was this translation helpful? Give feedback.
All reactions