-
Notifications
You must be signed in to change notification settings - Fork 5.7k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Request for fixing identified vulnerabilites in dependencies in ArgoCD 2.9.3 #16915
Comments
@rafariossaa please see our notes on security scanner results. I know a lot of compliance requirements these days say "you have to open an issue to track," so if that's the purpose, I understand. But if the intent is to actually ask for these issues to be fixed, then I would as that:
I do realize that those three steps aren't in SECURITY.md and that I should update that document. 🙂 |
What is the release cadence for |
Checklist:
argocd version
.Describe the bug
When running trivy on the ArgoCD
2.9.3
image, it reported the following CVEs in the modules used.To Reproduce
Run:
Screenshots
![Screenshot_20240118_173533](https://private-user-images.githubusercontent.com/11049367/297814971-469f437b-45d3-4889-a8b9-6fe7cf85ce02.png?jwt=eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJpc3MiOiJnaXRodWIuY29tIiwiYXVkIjoicmF3LmdpdGh1YnVzZXJjb250ZW50LmNvbSIsImtleSI6ImtleTUiLCJleHAiOjE3MzkwODMxMTksIm5iZiI6MTczOTA4MjgxOSwicGF0aCI6Ii8xMTA0OTM2Ny8yOTc4MTQ5NzEtNDY5ZjQzN2ItNDVkMy00ODg5LWE4YjktNmZlN2NmODVjZTAyLnBuZz9YLUFtei1BbGdvcml0aG09QVdTNC1ITUFDLVNIQTI1NiZYLUFtei1DcmVkZW50aWFsPUFLSUFWQ09EWUxTQTUzUFFLNFpBJTJGMjAyNTAyMDklMkZ1cy1lYXN0LTElMkZzMyUyRmF3czRfcmVxdWVzdCZYLUFtei1EYXRlPTIwMjUwMjA5VDA2MzMzOVomWC1BbXotRXhwaXJlcz0zMDAmWC1BbXotU2lnbmF0dXJlPTcwYjBlYzUxODUwYzNiZWI2M2RjNTYxZWY4M2NhZjBiMzk0ZjgxMjlkMDQ2OGExMTU1YTkwYmJlZDUxZGM5YTYmWC1BbXotU2lnbmVkSGVhZGVycz1ob3N0In0.NW6DlC5ds4xkj0b9uBtiHK6VDHZspTYpKNN7j9oDWuQ)
Version
The text was updated successfully, but these errors were encountered: