kompose icon indicating copy to clipboard operation
kompose copied to clipboard

[chore] update packages to fix trivy vulnerability scan

Open hookenz opened this issue 3 years ago • 1 comments

Trivy reports a long list of vulnerabilities. See issue here: https://github.com/kubernetes/kompose/issues/1507

After updating packages in go.mod, trivy now shows the following output:

❯ trivy fs .                        
2022-06-13T15:08:58.314+1200	INFO	Number of language-specific files: 2
2022-06-13T15:08:58.314+1200	INFO	Detecting bundler vulnerabilities...
2022-06-13T15:08:58.314+1200	INFO	Detecting gomod vulnerabilities...

docs/Gemfile.lock (bundler)

Total: 0 (UNKNOWN: 0, LOW: 0, MEDIUM: 0, HIGH: 0, CRITICAL: 0)


go.mod (gomod)

Total: 0 (UNKNOWN: 0, LOW: 0, MEDIUM: 0, HIGH: 0, CRITICAL: 0)

It wasn't exactly straight forward. I had to add some overrides!

hookenz avatar Jun 13 '22 03:06 hookenz

[APPROVALNOTIFIER] This PR is NOT APPROVED

This pull-request has been approved by: hookenz To complete the pull request process, please assign cdrage after the PR has been reviewed. You can assign the PR to them by writing /assign @cdrage in a comment when ready.

The full list of commands accepted by this bot can be found here.

Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment Approvers can cancel approval by writing /approve cancel in a comment

k8s-ci-robot avatar Jun 13 '22 03:06 k8s-ci-robot

Thank you so much! I can confirm that this compiles and works well.

Sorry about the delay, the project has long been in "maintenance" mode.

Unfortunately I do not have the bandwidth to update to the newest Go version only because there was compiling issues with the most up to date version with Kompose. But I'll merge this PR in and thanks again for the fixes!

cdrage avatar Aug 26 '22 13:08 cdrage