Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

updated chartmuseum image contains security vulnerability(CVE-2022-37434-zlib) #618

Closed
prasoon-pxc opened this issue Sep 8, 2022 · 3 comments

Comments

@prasoon-pxc
Copy link

Found Zlib security vulnerability on alpine image which is using as a base image in chart-museum image.

Minor fix may be available in alpine:3.13 image

Vulnerability Details --> https://access.redhat.com/security/cve/CVE-2022-37434

Chart-museum Image --> ghcr.io/helm/chartmuseum:v0.15.0

@scbizu
Copy link
Contributor

scbizu commented Sep 11, 2022

#568

@scbizu scbizu closed this as completed Sep 11, 2022
@scbizu
Copy link
Contributor

scbizu commented Sep 11, 2022

We will update the alphine version until our next release , if you need to use the latest version of alpine , you can use our HEAD version

@prasoon-pxc
Copy link
Author

@scbizu --> Can't we use versioned alpine image instead of latest, because this vulnerability is fix in alpine:3.13 , but if we use latest tag than it will never use 3.13 tag, or maybe I do not know if above vulnerability fix is available in latest image tag of alpine or not.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants