Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Upgrading to latest alpine #100

Merged
merged 2 commits into from
Nov 26, 2019
Merged

Upgrading to latest alpine #100

merged 2 commits into from
Nov 26, 2019

Conversation

adusumillipraveen
Copy link
Contributor

Currently Kured is being reported with having security vulnerabilities by our CSP because of the base image.

@adusumillipraveen adusumillipraveen changed the title Upgrading to latest alpine and kubectl Upgrading to latest alpine Nov 22, 2019
@bboreham
Copy link
Contributor

If they can tell us how those vulnerabilities can be exploited, that would be interesting.

However I don't wish to make a fuss.

@bboreham bboreham merged commit f2ae011 into kubereboot:master Nov 26, 2019
@adusumillipraveen
Copy link
Contributor Author

Thanks @bboreham . It just scans the docker image for known vulnerabilities ( static analysis ) . So, it was detecting a high scored vulnerability CVE-2019-14697 ( raised and fixed originally in musl library). alpinelinux/docker-alpine#34. Always good to keep the noise low on these things :)

@bboreham
Copy link
Contributor

This is precisely my point - it is pure noise.
The CVE you refer to was an i386-only bug.

@dholbach dholbach mentioned this pull request Feb 4, 2020
@dholbach dholbach added this to the 1.3.0 milestone Feb 4, 2020
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants