-
Notifications
You must be signed in to change notification settings - Fork 2.5k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
CVEs in Portainer CE #6342
Comments
Thanks for highlighting this. We have flagged this internally with our team and we will be tackling them with the next release. |
That would be great! Thanks |
Thanks again for highlighting this issue. We have fixed trivy Helm and Portainer vulnerabilities relating to direct dependencies for our next releases. We have tried using the latest Kompose binary, but it doesn't fix the reported vulnerabilities and adds more vulnerabilities. Hence, we chose to not change Kompose binary for now and will look into a fix in future, but ideally wait for Kompose's fix at their side. |
Thanks for addressing some of the vulnerabilities, all your effort is
really appreciated... Since container/ image scanning and the process of
understanding, follow-up, and whitelisting any findings is mandatory before
we can/ may use the container. Regards, Dennis
Op zo 20 feb. 2022 om 23:14 schreef mariyam-portainer <
***@***.***>:
… Thanks again for highlighting this issue. We have fixed trivy Helm and
Portainer vulnerabilities relating to direct dependencies for our next
releases. We have tried using the latest Kompose binary, but it doesn't fix
the reported vulnerabilities and adds more vulnerabilities. Hence, we
choose to not change Kompose binary for now and will look into a fix in
future, but ideally wait for Komponse's fix at their side.
—
Reply to this email directly, view it on GitHub
<#6342 (comment)>,
or unsubscribe
<https://github.com/notifications/unsubscribe-auth/ABHSXR2VNOJOQQJRYULV4V3U4FRVRANCNFSM5K7SRVIQ>
.
Triage notifications on the go with GitHub Mobile for iOS
<https://apps.apple.com/app/apple-store/id1477376905?ct=notification-email&mt=8&pt=524675>
or Android
<https://play.google.com/store/apps/details?id=com.github.android&referrer=utm_campaign%3Dnotification-email%26utm_medium%3Demail%26utm_source%3Dgithub>.
You are receiving this because you authored the thread.Message ID:
***@***.***>
|
Bug description
Please fix the vulnerabilities and one compliance finding:
Expected behavior
All the CVEs are addressed and fixed in future release(s).
Portainer Logs
N/A
Steps to reproduce the issue:
N/A
Technical details:
docker run -p 9443:9443 portainer/portainer
): N/AAdditional context
The text was updated successfully, but these errors were encountered: