Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Address reported CVEs in Temporal UI 2.33 #2484

Open
bbemis017 opened this issue Jan 3, 2025 · 0 comments
Open

Address reported CVEs in Temporal UI 2.33 #2484

bbemis017 opened this issue Jan 3, 2025 · 0 comments
Labels
bug Something isn't working

Comments

@bbemis017
Copy link

Describe the bug
There are a few security vulnerabilities being reported in the go stdlib version that the temporal UI uses. It would be ideal if Temporal UI could upgrade out of these vulnerabilities in the next version

https://nvd.nist.gov/vuln/detail/cve-2023-45288
https://nvd.nist.gov/vuln/detail/CVE-2024-24788
https://nvd.nist.gov/vuln/detail/CVE-2024-24787

To Reproduce
Pull down the temporal ui from docker
Run a grype image scan on the docker image

Expected behavior
grype scan should not report any vulnerabilities in the image

Screenshots
Untitled 4

Additional context
Add any other context about the problem here.

@bbemis017 bbemis017 added the bug Something isn't working label Jan 3, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug Something isn't working
Projects
None yet
Development

No branches or pull requests

1 participant