-
Notifications
You must be signed in to change notification settings - Fork 3.7k
Open
Labels
Stalearea/securitytype/bugThe PR fixed a bug or issue reported a bugThe PR fixed a bug or issue reported a bug
Description
Search before asking
- I searched in the issues and found nothing similar.
Version
v2.10.2
Minimal reproduce step
look into trivy powered inspection for vulnerabilities
at artifacthub.io
https://artifacthub.io/packages/helm/apache/pulsar?modal=security-report
open details of in the latest helm chart v3.0.0 included pulsar v2.10.2 image
What did you expect to see?
very few fixable vulnerabilities, since v2.10.2 was released just 8 days ago https://github.com/apache/pulsar/releases
What did you see instead?
- 72 vulnerabilities have been detected in the image
- 35 of these should be fixable (most with a version bump of dependencies)
Anything else?
- this is related to
[Security] v2.10.2 contains up to 9 year old vulnerabilities/CVEs -> get rid of the oldest #18338 - this is a follow up of
Arguments for "why pulsar is secure?" #18041 - this is part of
[security] further reduction of the 136 vulnerabilities (79 fixable) in helm chart v3.0.0 pulsar-helm-chart#334
Are you willing to submit a PR?
- I'm willing to submit a PR!
Metadata
Metadata
Assignees
Labels
Stalearea/securitytype/bugThe PR fixed a bug or issue reported a bugThe PR fixed a bug or issue reported a bug

