kiwigrid/k8s-sidecar

vulnerabilities in libcrypto and libssl libraries

marianobilli opened this issue · 3 comments

Upon running a trivy vulnerability scan with

docker run --rm -v trivy-cache:/root/.cache/ -v /var/run/docker.sock:/var/run/docker.sock aquasec/trivy:latest image kiwigrid/k8s-sidecar

Both libraries should be bumped to, at least, version 1.1.1t-r2
Screenshot 2023-03-31 at 10 32 57

Thanks

jekkel commented

Thanks for the report, can you please check whether our upstream base image is affected as well?

bt909 commented

This issue is solved with the actual image, I think, but there are new findings.
see: #299

But I think this issue can be closed.

yeah, let me close this issue and we'll continue it in #299