Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Found security vulnerability in chartmuseum v0.15.0 #604

Closed
Kiran-38 opened this issue Jul 20, 2022 · 1 comment
Closed

Found security vulnerability in chartmuseum v0.15.0 #604

Kiran-38 opened this issue Jul 20, 2022 · 1 comment

Comments

@Kiran-38
Copy link

Hi,
The chartMuseum binary contains the go.etcd.io/etcd-v3.3.27+incompatible, github.com/containerd/containerd-v1.6.1 library with is flagged as a security risk and need to update to the latest version available for resolving the issue.

The mentioned library is coming as a derived dependency, as is verified by searching for it in the go.mod file. It is because of this vulnerable library that all the images having even the latest chartMuseum binary baked into them are failing the security scans.

@scbizu
Copy link
Contributor

scbizu commented Jul 21, 2022

#568

@scbizu scbizu closed this as completed Jul 21, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants