Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Bug: A lot of CVEs in the devtron images (Fixable!) #6311

Open
2 tasks done
rirze opened this issue Jan 17, 2025 · 0 comments
Open
2 tasks done

Bug: A lot of CVEs in the devtron images (Fixable!) #6311

rirze opened this issue Jan 17, 2025 · 0 comments
Assignees
Labels
bug Something isn't working needs-triage Issue is not approved or ready-to-work on

Comments

@rirze
Copy link

rirze commented Jan 17, 2025

📜 Description

You check the full report here:
https://artifacthub.io/packages/helm/devtron/devtron-operator

Image

There's an abnormal amount of fixabled CVEs in the docker images that I see here. I'm pretty sure running a package manager update would fix many of these issues.

The reason I bring this up is so I can showcase this application for my company project, but if they see the current security report, they will 100% deny its adoption. If a lot of these could be fixed, it would my case better.

👟 Reproduction steps

Go to https://artifacthub.io/packages/helm/devtron/devtron-operator
Then click on "Full Report":

Image

👍 Expected behavior

It should not have so many vulnerabilities.

👎 Actual Behavior

It has a lot of vulnerabilities.

☸ Kubernetes version

Any.

Cloud provider

Any.

🌍 Browser

Chrome

🧱 Your Environment

No response

✅ Proposed Solution

Perform docker image OS updates and update service dependencies so that CVEs are mitigated.

👀 Have you spent some time to check if this issue has been raised before?

  • I checked and didn't find any similar issue

🏢 Have you read the Code of Conduct?

@rirze rirze added bug Something isn't working needs-triage Issue is not approved or ready-to-work on labels Jan 17, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug Something isn't working needs-triage Issue is not approved or ready-to-work on
Projects
None yet
Development

No branches or pull requests

3 participants