-
Notifications
You must be signed in to change notification settings - Fork 5k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Security Vulnerabilities #5850
Comments
Hi, unfortunately, those security vulnerabilities are not fixed by the OS or the application itself, so although we built the images on a regular basis to provide the latest version of system packages, this kind of CVE will be reported while there is no new version patching the issue in the OS or the application. At this moment there is not any fixable vulnerability in the container image $ trivy image --ignore-unfixed bitnami/cluster-autoscaler:1.25.0
2022-09-09T08:02:09.990Z INFO Vulnerability scanning is enabled
2022-09-09T08:02:09.990Z INFO Secret scanning is enabled
2022-09-09T08:02:09.990Z INFO If your scanning is slow, please try '--security-checks vuln' to disable secret scanning
2022-09-09T08:02:09.990Z INFO Please see also https://aquasecurity.github.io/trivy/v0.31.2/docs/secret/scanning/#recommendation for faster secret detection
2022-09-09T08:02:16.848Z INFO Detected OS: debian
2022-09-09T08:02:16.848Z INFO Detecting Debian vulnerabilities...
2022-09-09T08:02:16.861Z INFO Number of language-specific files: 1
2022-09-09T08:02:16.861Z INFO Detecting gobinary vulnerabilities...
bitnami/cluster-autoscaler:1.25.0 (debian 11.4)
Total: 0 (UNKNOWN: 0, LOW: 0, MEDIUM: 0, HIGH: 0, CRITICAL: 0) The Bitnami Application Catalog (OpenSource) is based on Debian 11 but Bitnami, as part of VMware, provides a custom container and Helm Charts catalog based on the desired base image (generic distro such as Debian 10 & 11, CentOS 7, PhotonOS 3 & 4, Ubuntu 18.04, 20.04 & 22.04, or custom golden image) through the VMware Tanzu Application Catalog. |
This Issue has been automatically marked as "stale" because it has not had recent activity (for 15 days). It will be closed if no further activity occurs. Thanks for the feedback. |
Due to the lack of activity in the last 5 days since it was marked as "stale", we proceed to close this Issue. Do not hesitate to reopen it later if necessary. |
Prisma scan reports another CVE:
|
Name and Version
bitnami/cluster-autoscaler:1.25.0
What steps will reproduce the bug?
Vulnerabilities scanned by PRISMA tool
What is the expected behavior?
No response
What do you see instead?
Additional information
No response
The text was updated successfully, but these errors were encountered: