Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

CVEs in latest version #181

Open
M4tteoP opened this issue Mar 26, 2024 · 3 comments · May be fixed by #182
Open

CVEs in latest version #181

M4tteoP opened this issue Mar 26, 2024 · 3 comments · May be fixed by #182

Comments

@M4tteoP
Copy link

M4tteoP commented Mar 26, 2024

Hi there,
The following CVEs have been reported by scanning kubegres:

Severity CVE Package Fix
HIGH PRISMA-2022-0227 github.com/emicklei/go-restful/v3 v3.9.0 -> v3.10.0
HIGH CVE-2023-44487 golang.org/x/net v0.13.0 -> v0.17.0
HIGH CVE-2023-39325 golang.org/x/net/http2 v0.13.0 -> v0.17.0

It would be great to update the mentioned dependencies and fix them, I'm opening a PR to fix this issue.

@alex-arica
Copy link
Member

Thank you. I will upgrade Kubegres to the latest version of Kubebuilder which should fix the CVEs.
I am just waiting on them to release a new version which should be soon.

@M4tteoP M4tteoP linked a pull request Mar 26, 2024 that will close this issue
@M4tteoP
Copy link
Author

M4tteoP commented Mar 26, 2024

Thanks @alex-arica! Please, feel free to close the just opened PR if you are already addressing it in other ways!

@alex-arica
Copy link
Member

Considering the average release cycle of Kubebuilder is 3 months, the next release should happen by the 30th April. Perhaps it would be a long wait.

I will check your PR this week and run it against all acceptance tests.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging a pull request may close this issue.

2 participants