Jin Ahn

Results 27 comments of Jin Ahn

I don't believe this actually works in my package.json I had ``` "dependencies": { "@cdktf/provider-aws": "^9.0.0", "@cdktf/provider-null": "^2.0", "cdktf": "^0.12.0", ``` I upgraded my cdktf-cli to 14.3. I ran `npm...

I also am facing this issue from cdktf. Below is portion of my config This makes using terraform for production NACL highly unusable. ``` egress: [ { ruleNo: 1, protocol:...

@coffee-squirrel are there plans to patch the other vulnerabilites i have shown?

Hi, just thought I'd give an update. I've checked the latest 5.0 rc2 image for vulnerabilities. and although there is an improvement the critical ones still remain. I understand that...

Hi @kroepke, just to confirm - are their still plans to patch the remaining vulnerabilites? Or are we leaving them alone? ![image](https://user-images.githubusercontent.com/66384196/210898344-6b112fa2-6570-4eec-b96c-d0581a4a41cb.png)

Most recent update of 5.0.3 is vastly improved. Just 1 critical vulnerability remaining. Need to `update json-smart to 2.4.1`

New vulnerablities have come out that impact graylog image. I know the shiro-core doesn't apply but there are others ![image](https://user-images.githubusercontent.com/66384196/223577304-61ae7826-e9b9-4f05-9682-c3d9b9ca04b4.png)

Hi. 5.0.6 also has new vulnerablities related to org.quartz-scheduler and org.yaml:snakeyaml https://nvd.nist.gov/vuln/detail/CVE-2019-13990 https://nvd.nist.gov/vuln/detail/CVE-2022-1471 ![image](https://user-images.githubusercontent.com/66384196/233476942-0c6011e3-51cc-4029-a372-883245d21efc.png)

5.0.7 has 6 critical and 11 high vulnerabilities ![image](https://github.com/Graylog2/graylog-docker/assets/66384196/47bf7e66-4410-466c-9f70-6fdcf023d452)