argocd-image-updater icon indicating copy to clipboard operation
argocd-image-updater copied to clipboard

Container Image CVEs - v0.12

Open larntz opened this issue 2 years ago • 0 comments

There are critical CVEs in the argocd-image-updater container.

Image tagged v0.12.0. Most of these have been fixed; see here and here

image


Hello, Our security team is asking us to get these CVEs remediated. These issues are not with argocd-image-updater itself, but rather the base image. I am reporting this here based on this line in the security policy:

Please report issues with our container image directly on the GitHub tracker if the issue has already been assigned a CVE.

Is there any chance of a new release for version v0.12.0 with an updated base image?

larntz avatar Jun 14 '22 14:06 larntz