Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

CVE-2022-1996, CVE-2023-39325, CVE-2022-21698, CVE-2023-44487, SNYK-GOLANG-GITHUBCOMEMICKLEIGORESTFULV3-2435654, GHSA-m425-mq94-257g, CVE-2023-45142, CVE-2019-3826, CVE-2023-3978 #1358

Open
maochuanli opened this issue Nov 9, 2023 · 3 comments
Labels
kind/feature Categorizes issue or PR as related to a new feature. triage/accepted Indicates an issue or PR is ready to be actively worked on.

Comments

@maochuanli
Copy link

What would you like to be added:

Fix vulnerabilities issues.

Why is this needed:

/kind feature

@k8s-ci-robot k8s-ci-robot added kind/feature Categorizes issue or PR as related to a new feature. needs-triage Indicates an issue or PR lacks a `triage/foo` label and requires one. labels Nov 9, 2023
@dgrisonnet
Copy link
Member

/triage accepted

@k8s-ci-robot k8s-ci-robot added triage/accepted Indicates an issue or PR is ready to be actively worked on. and removed needs-triage Indicates an issue or PR lacks a `triage/foo` label and requires one. labels Nov 16, 2023
@cpanato
Copy link
Member

cpanato commented Nov 24, 2023

this issue does not help much, i know there is a couple of cves to fix, this this should be written in a little better way

@ricardoapl
Copy link
Member

I believe most (if not all) of these don't affect https://github.com/kubernetes-sigs/metrics-server/releases/tag/v0.7.1

Should we close this issue?

Also CVE-2019-3826 doesn't affect metrics-server, was withdrawn because it doesn't apply to the Prometheus go package

Perhaps we can use VEX in the future to communicate this to users instead

#1499

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
kind/feature Categorizes issue or PR as related to a new feature. triage/accepted Indicates an issue or PR is ready to be actively worked on.
Projects
None yet
Development

No branches or pull requests

5 participants