Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Found security vulnerability in chartmuseum v0.15.0 #607

Closed
Kiran-38 opened this issue Jul 29, 2022 · 2 comments
Closed

Found security vulnerability in chartmuseum v0.15.0 #607

Kiran-38 opened this issue Jul 29, 2022 · 2 comments

Comments

@Kiran-38
Copy link

Kiran-38 commented Jul 29, 2022

Hi,
The chartMuseum binary contains the go.etcd.io/etcd-v3.3.27+incompatible library with is flagged as a security risk and need to update to the latest version 3.4.0 and above available for resolving the issue.

The mentioned library is coming as a derived dependency, as is verified by searching for it in the go.mod file. It is because of this vulnerable library that all the images having even the latest chartMuseum binary baked into them are failing the security scans.

@nerdeveloper
Copy link
Member

Hello @Kiran-38 thank you for reporting this. @cbuto, please, I can see we have this showing in our scans:

https://github.com/helm/chartmuseum/security/dependabot/22

@nerdeveloper
Copy link
Member

This issue is being tracked here: #568

scbizu added a commit that referenced this issue Sep 13, 2022
scbizu added a commit that referenced this issue Sep 13, 2022
scbizu added a commit that referenced this issue Sep 13, 2022
scbizu added a commit that referenced this issue Sep 13, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging a pull request may close this issue.

2 participants