Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Pulumi-python docker image have many vulnerabilities that needs to be fixed #206

Open
abhishekmahajan0709222 opened this issue Jul 11, 2024 · 1 comment
Labels
impact/security kind/bug Some behavior is incorrect or out of spec

Comments

@abhishekmahajan0709222
Copy link

What happened?

We are using pulumi-python image as base in our dockerfile

Upon running trivy scan, we found some critical and high vulnerabilities with some packages

  1. Libexpat1(CVE-2023-52425)
  2. zlib1g(CVE-2023-45853)

Example

N/A

Output of pulumi about

N/A

Additional context

No response

Contributing

Vote on this issue by adding a 👍 reaction.
To contribute a fix for this issue, leave a comment (and link to your pull request, if you've opened one already).

@abhishekmahajan0709222 abhishekmahajan0709222 added kind/bug Some behavior is incorrect or out of spec needs-triage Needs attention from the triage team labels Jul 11, 2024
@justinvp justinvp added impact/security and removed needs-triage Needs attention from the triage team labels Jul 17, 2024
@justinvp
Copy link
Member

Thanks for the heads-up! We're looking into it.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
impact/security kind/bug Some behavior is incorrect or out of spec
Projects
None yet
Development

No branches or pull requests

2 participants