Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[grafana] Fix for cve-2021-25742 is incorrect - not fixable here #1542

Closed
afirth opened this issue Jun 28, 2022 · 1 comment · Fixed by #1543
Closed

[grafana] Fix for cve-2021-25742 is incorrect - not fixable here #1542

afirth opened this issue Jun 28, 2022 · 1 comment · Fixed by #1543

Comments

@afirth
Copy link
Contributor

afirth commented Jun 28, 2022

#1481 introduced allow-snippet-annotations: false all configmaps in the chart. However, this configuration is only a valid input to ingress-nginx, via it's configmap (not modified or created by any chart in this repo). It looks like this linter is incorrectly flagging it - maybe that's why the change was made.

The correct fix is documented in the description of kubernetes/kubernetes#126811 under Mitigation and is outside the scope of this repository.

Suggest fix: kubernetes/ingress-nginx#1543 (reverts kubernetes/ingress-nginx#1481)

@afirth
Copy link
Contributor Author

afirth commented Jun 28, 2022

attention @zanac1986 @zanhsieh

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging a pull request may close this issue.

2 participants
@afirth and others