Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Found security vulnerability in chartmuseum v0.15.0 #631

Closed
Kiran-38 opened this issue Oct 12, 2022 · 4 comments
Closed

Found security vulnerability in chartmuseum v0.15.0 #631

Kiran-38 opened this issue Oct 12, 2022 · 4 comments

Comments

@Kiran-38
Copy link

Kiran-38 commented Oct 12, 2022

Hi,
The chartMuseum binary contains the helm.sh/helm/v3 v3.9.3 library with is flagged as a security risk and need to update to the latest version 3.9.4 or later and above available for resolving the issue.

The mentioned library is coming as a derived dependency, as is verified by searching for it in the go.mod file. It is because of this vulnerable library that all the images having even the latest chartMuseum binary baked into them are failing the security scans.

I believe there is a branch created for https://github.com/helm/chartmuseum/blob/dependabot/go_modules/helm.sh/helm/v3-3.10.0/go.mod it already, if possible can you please give when can we expect the fix. Thanks

@scbizu
Copy link
Contributor

scbizu commented Oct 12, 2022

Could you put this kind of security issue to our pining issue : #568 , the dependabot PR I will review and merge it ASAP . Thank you again ~

@cbuto
Copy link
Contributor

cbuto commented Jan 6, 2023

It looks like this should be resolved now and the next release of ChartMuseum will include the updated dependency. Can we close this @scbizu @Kiran-38?

@Kiran-38
Copy link
Author

Kiran-38 commented Jan 6, 2023

Yes, I believe we can close. May I know when can we expect the next release version of chartmuseum changes.

@Kiran-38
Copy link
Author

Hi @cbuto any latest version going to be available as the tar bundle in the release (v0.15.0) is in july. Can you please give me some tentative time when it can be released. It will be appreciated if there is any release in this month end or so. Waiting for the update. Thanks

@scbizu scbizu closed this as completed Mar 6, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants