Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Need upgraded versions of following libraries to resolve security vulnerabilities #137

Open
sivani01 opened this issue Feb 7, 2025 · 0 comments

Comments

@sivani01
Copy link

sivani01 commented Feb 7, 2025

we are currently using operator-sdk v1.37.1 as the base image to build our operator. During our Security scan we got below mentioned security vulnerabilities

cve package current version fixed version
CVE-2024-10963 pam 1.5.1-22.el9_5 1.5.1-23.el9_4
CVE-2019-12900 bzip2-libs 1.0.8-8.el9 1.0.8-8.el9_4.1
CVE-2023-2728 python3-decorator 4.4.2-6.el9 4.4.2-6.0.el9
CVE-2024-28863 libcomps 0.1.18-1.el9 0.1.21-1.el9pc
CVE-2024-28863 python3-chardet 4.0.0-5.el9 5.0.0-2.el9pc
CVE-2024-28863 python3-dateutil 2.8.1-7.el9 2.8.2-5.el9pc
CVE-2024-28863 python3-libcomps 0.1.18-1.el9 0.1.21-1.el9pc
CVE-2024-28863 python3-requests 2.25.1-8.el9 2.31.0-4.el9pc
CVE-2024-28863 python3-six 1.15.0-9.el9 1.16.0-5.el9pc
CVE-2024-28863 python3-urllib3 1.26.5-6.el9 2.2.3-1.el9pc

Can we know by when the new version of operator-sdk will be released with the upgraded version of these packages?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant