Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Image Vulnerability] Vulnerabilities Found in "ghcr.io/kanisterio/es-sidecar" Image (Example image) #2755

Closed
hairyhum opened this issue Mar 15, 2024 · 2 comments
Labels
security Security related issues upstream-security

Comments

@hairyhum
Copy link
Contributor

Container Image Vulnerability Report

Container vulnerability scanner found 8 vulnerabilities in es-sidecar image:

https://github.com/kanisterio/kanister/actions/runs/8301336368/job/22721234585

Vulnerability status

Currently vulnerabilities exist in upstream NPM package elasticdump

@hairyhum hairyhum added security Security related issues upstream-security labels Mar 15, 2024
Copy link
Contributor

Thanks for opening this issue 👍. The team will review it shortly.

If this is a bug report, make sure to include clear instructions how on to reproduce the problem with minimal reproducible examples, where possible. If this is a security report, please review our security policy as outlined in SECURITY.md.

If you haven't already, please take a moment to review our project's Code of Conduct document.

@hairyhum hairyhum removed the triage label Apr 11, 2024
@hairyhum hairyhum changed the title [Image Vulnerability] High/Critical Severity Vulnerabilities Found in "ghcr.io/kanisterio/es-sidecar" Image [Image Vulnerability] Vulnerabilities Found in "ghcr.io/kanisterio/es-sidecar" Image (Example image) Jun 12, 2024
@hairyhum
Copy link
Contributor Author

hairyhum commented Aug 20, 2024

Wont fix: elasticdump tool used in the image is not being updated upstream. The image should only be used in examples.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
security Security related issues upstream-security
Projects
Status: Done
Development

No branches or pull requests

1 participant