You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
We are encountering the vulnerability of CVE-2023-44487 for the image gardendev/buildkit:v0.12.2. Can you please provide me with the resolution for this issue?
#6506
We are encountering the vulnerability of CVE-2023-44487 for the image gardendev/buildkit:v0.12.2. Can you please provide me with the resolution for this issue?
The text was updated successfully, but these errors were encountered:
Hi @SiddharamAlagi,
we are working on updating the image since it's still present in the latest tag (v0.13.2). It will be released with the next release.
Also, just to make sure I understand the issue: are you experiencing the vulnerability or it's just being flagged by your security setup?
Hi @SiddharamAlagi , no that is currently not possible. I have updated the image to the latest buildkit image. Once it is merged you can use the garden edge version to already use the new image. We will also cut a new garden release today, which will make the fix generally available.
@SiddharamAlagi the fix was released in Garden 0.13.42 yesterday.
Now Garden uses moby/builtkit:0.16.0 as a base image and that one does not have the vulnerability mentioned above.
Please let us know if there are any other issues.
We are encountering the vulnerability of CVE-2023-44487 for the image gardendev/buildkit:v0.12.2. Can you please provide me with the resolution for this issue?
The text was updated successfully, but these errors were encountered: