-
Notifications
You must be signed in to change notification settings - Fork 187
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Vulnerabilities reported by Mend in 1.27.6 #361
Comments
thx for the report. i just rescan the current image using |
Hi @ChristianGeie, may I know if CVE-2024-45492 has been fixed in kiwigrid/k8s-sidecar:1.28.0? |
@vvxxvvxx CVE-2024-45492 should be fixed in k8s-sidecar:1.28.0 |
Hi @ChristianGeie , we can see the CVE-2024-45490, CVE-2024-45491 and CVE-2024-45492 vulnerabilities are still in k8s-sidecar:1.28.0. do you have any plan to fix them? |
opened an issue #370 |
Mend reports the vulnerabilities listed below:
python-Python-3.12.5
:pip-24.2-py3-none-any.whl
When I run the image locally, it does appear that the venv uses Python 3.12.5:
However, I manually ran the base image (
python:alpine3.20
) and ran the steps in the Dockerfile manually, and that resulted in the Python venv using version 3.12.6, which I believe has fixes for at least some of these.The text was updated successfully, but these errors were encountered: