You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
The default install for the operator runs a sidecar HTTP proxy for the controller manager using kube-rbac-proxy. Currently this is pulled from gcr.io/kubebuilder/kube-rbac-proxy using the v0.8.0 tag and has a number of CVEs in its dependencies, see attached example ouput from my image security scan. kube-rbac-proxy-cves.md
Issue
The default install for the operator runs a sidecar HTTP proxy for the controller manager using kube-rbac-proxy. Currently this is pulled from gcr.io/kubebuilder/kube-rbac-proxy using the
v0.8.0
tag and has a number of CVEs in its dependencies, see attached example ouput from my image security scan.kube-rbac-proxy-cves.md
The repository currently in use doesn't have a tag for the latest release of kube-rbac-proxy
0.11.0
from 2021-08-02: https://github.com/brancz/kube-rbac-proxy/releasesResolution
Update to use a different repository that has the latest tags, potentially bitnami/kube-rbac-proxy and update to the current latest version
0.11.0
The text was updated successfully, but these errors were encountered: