Skip to content

[Security] v2.10.2 contains 35 fixable vulnerabilities #18348

@hpvd

Description

@hpvd

Search before asking

  • I searched in the issues and found nothing similar.

Version

v2.10.2

Minimal reproduce step

look into trivy powered inspection for vulnerabilities
at artifacthub.io
https://artifacthub.io/packages/helm/apache/pulsar?modal=security-report

open details of in the latest helm chart v3.0.0 included pulsar v2.10.2 image

What did you expect to see?

very few fixable vulnerabilities, since v2.10.2 was released just 8 days ago https://github.com/apache/pulsar/releases

What did you see instead?

  • 72 vulnerabilities have been detected in the image
  • 35 of these should be fixable (most with a version bump of dependencies)

2022-11-04_17h06_11

2022-11-04_17h03_17

Anything else?

Are you willing to submit a PR?

  • I'm willing to submit a PR!

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions