karma icon indicating copy to clipboard operation
karma copied to clipboard

Vulnerability found with an analysis trivy

Open TACY-octo opened this issue 2 years ago • 0 comments

Hello,

Karma have two critical vulnerability on image base "gcr.io/distroless/base".

trivy image --ignore-unfixed ghcr.io/prymitive/karma:v0.103

ghcr.io/primitive/karma:v0.103 (debian 11.3)
===========================================
Total: 2 (UNKNOWN: 0, LOW: 0, MEDIUM: 0, HIGH: 0, CRITICAL: 2)

Can you rebuild and release the image to include the security patchs from "gcr.io/distroless/base" ?

Best regard

Cyril

TACY-octo avatar Jun 15 '22 09:06 TACY-octo