Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

CVE issues #1066

Open
Ravikirandg29 opened this issue Mar 10, 2025 · 3 comments
Open

CVE issues #1066

Ravikirandg29 opened this issue Mar 10, 2025 · 3 comments

Comments

@Ravikirandg29
Copy link

When is the official release date for next chart museum version? As the previous 0.16.2 has many critical CVE issues.

@scbizu
Copy link
Contributor

scbizu commented Mar 10, 2025

@Ravikirandg29 Hi , could you provide much more report details about those CVEs , some of these are upstream issues , we received tons of PRs from dependabot to update our dependencies daily which really cause the spam (most of these update the indirect dependency) , we will try to resolve the spam next , so , if you have the CVEs list , we can help with it by bumping up some of the massive dependencies and maybe work out a release .

@Ravikirandg29
Copy link
Author

Ravikirandg29 commented Mar 10, 2025

@scbizu Below are the critical issues which were reported in the current chartm 0.16.2 version which we are using.
Just wanted to know if there is any release planned with this fix. Since the last official release was on jul 2024.
CVE-2024-41110
Recommendation:
Upgrade github.com/docker/docker from v24.0.9+incompatible to 25.0.6 to fix the vulnerability.

CVE-2024-45337
Recommendation:
Upgrade golang.org/x/crypto from v0.21.0 to 0.31.0 to fix the vulnerability.

@scbizu
Copy link
Contributor

scbizu commented Mar 11, 2025

@Ravikirandg29 I think I fixed this , you can try our canary image . As for next rc , I am working on the other fix #1051 to be merged. Maybe this weekend or 1w later .

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants