Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Flagger loadtester no updated release #1245

Closed
AshDerTest opened this issue Aug 1, 2022 · 0 comments · Fixed by #1246
Closed

Flagger loadtester no updated release #1245

AshDerTest opened this issue Aug 1, 2022 · 0 comments · Fixed by #1246
Assignees

Comments

@AshDerTest
Copy link

Describe the bug

I am using v1.22.0 of flagger and 0.22 of flagger loadtester. I noticed that the last update was done 5 months ago. Running this through a security scan highlights a bunch of vunerabilites (alpine, go, bash, etc) which have been updated in later versions.

I did see an update being done to the dockerfile but no official release of image to be used.

Would it be possible to update the versions of base images used and provide an newer release ?

Some of the errors picked up:

  • | CVE | CVSS | PACKAGE | VERSION | STATUS
  •  CVE-2022-32207 | 9.80 | curl | 7.80.0-r0 | fixed in 7.80.0-r2
    
  • CVE-2022-28391 | 9.80 | busybox | 1.34.1-r3 | fixed in 1.34.1-r5
  • CVE-2022-23806 | 9.10 | go | 1.17.2 | fixed in 1.17.7, 1.16.14
  • CVE-2022-23806 | 9.10 | go | 1.16.10 | fixed in 1.17.7, 1.16.14
  • CVE-2022-21235 | 9.00 | github.com/Masterminds/vcs | v1.13.1 | fixed in 1.13.2
  • CVE-2022-22576 | 8.10 | curl | 7.80.0-r0 | fixed in 7.80.0-r1
  • CVE-2022-28327 | 7.50 | go | 1.17.8 | fixed in 1.18.1, 1.17.9
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging a pull request may close this issue.

2 participants