livenessprobe icon indicating copy to clipboard operation
livenessprobe copied to clipboard

CVE-2024-45338

Open kamkaur30 opened this issue 8 months ago • 2 comments

We would need to have the CVE mitigated. Would it be possible to get new release with updated go versions?

kamkaur30 avatar Mar 10 '25 16:03 kamkaur30

@jsafrane Could you please help on this?

kamkaur30 avatar Mar 19 '25 07:03 kamkaur30

@jsafrane would you cut a new release soon? thanks.

andyzhangx avatar Mar 27 '25 03:03 andyzhangx

wait, let me merge this PR: https://github.com/kubernetes-csi/csi-release-tools/pull/274, and then update the csi-release-tools in this repo first.

andyzhangx avatar Apr 16 '25 02:04 andyzhangx

this PR should be merged first: https://github.com/kubernetes-csi/livenessprobe/pull/350

andyzhangx avatar Apr 17 '25 14:04 andyzhangx

Hey @jsafrane, following up on @kamkaur30, please share an update on this?

SUNNUWORKS avatar Apr 28 '25 17:04 SUNNUWORKS

@jsafrane can we cut a new release this month? it's clear now

# trivy image gcr.io/k8s-staging-sig-storage/livenessprobe:canary
2025-05-27T08:49:00.561Z        INFO    Vulnerability scanning is enabled
2025-05-27T08:49:00.561Z        INFO    Secret scanning is enabled
2025-05-27T08:49:00.561Z        INFO    If your scanning is slow, please try '--security-checks vuln' to disable secret scanning
2025-05-27T08:49:00.561Z        INFO    Please see also https://aquasecurity.github.io/trivy/v0.36/docs/secret/scanning/#recommendation for faster secret detection
2025-05-27T08:49:01.309Z        INFO    Detected OS: debian
2025-05-27T08:49:01.309Z        INFO    Detecting Debian vulnerabilities...
2025-05-27T08:49:01.309Z        INFO    Number of language-specific files: 1
2025-05-27T08:49:01.309Z        INFO    Detecting gobinary vulnerabilities...

gcr.io/k8s-staging-sig-storage/livenessprobe:canary (debian 12.11)

Total: 0 (UNKNOWN: 0, LOW: 0, MEDIUM: 0, HIGH: 0, CRITICAL: 0)

andyzhangx avatar May 27 '25 08:05 andyzhangx

registry.k8s.io/sig-storage/livenessprobe:v2.16.0 is out

/close

jsafrane avatar Jun 02 '25 15:06 jsafrane

@jsafrane: Closing this issue.

In response to this:

registry.k8s.io/sig-storage/livenessprobe:v2.16.0 is out

/close

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository.

k8s-ci-robot avatar Jun 02 '25 15:06 k8s-ci-robot