-
Notifications
You must be signed in to change notification settings - Fork 1.7k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
CVE-2021-36159 and CVE-2021-3711 #2326
Comments
@nunojusto Thanks for opening this issue. 2.30.1 will be released soon. |
Hi Márk, you forgot to tag the container image to v2.30.1 ... i'll assume it's the latest but it's not tagged to the minor version |
Forget what i've said. The CI is still progress. Sorry |
Hm, CI is failing for some reason. Sorry about that. |
Should be fixed |
alexmt
added a commit
to alexmt/argo-cd
that referenced
this issue
Jan 20, 2022
Signed-off-by: Alexander Matyushentsev <AMatyushentsev@gmail.com>
alexmt
pushed a commit
to argoproj/argo-cd
that referenced
this issue
Jan 20, 2022
Signed-off-by: Alexander Matyushentsev <AMatyushentsev@gmail.com>
6 tasks
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Preflight Checklist
Version
2.30.0
Storage Type
Kubernetes
Installation Type
Custom Helm chart
Expected Behavior
There are vulnerabilities CVE-2021-36159 and CVE-2021-3711 already corrected in base alpine3.14.2 version but not released in dex image (v2.30.0).
What we need is a new dex image release. I see the code is already bumped to have the latest alpine.
When are we releasing the next version? Is it soon?
Thank you
Actual Behavior
CVE-2021-36159 and CVE-2021-3711
Steps To Reproduce
No response
Additional Information
No response
Configuration
No response
Logs
No response
The text was updated successfully, but these errors were encountered: