-
Notifications
You must be signed in to change notification settings - Fork 250
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Official fluentbit image has CVEs #300
Comments
Thank you for your feedback, I would like to ask, is there an appeal bug in the fluent community images? |
@igajsin Would you test the official fluent bit image |
Yes, it has.
So, I'll readdress the issue in their repository |
@igajsin I think you can try the latest fluent/fluent-bit:1.9.3 release, and if still the same problem you can open a issue in fluent-bit repo |
There is a new issue in fluent-bit repo: fluent/fluent-bit-docker-image#53 Thanks for your support. |
Describe the bug
Hi. I've made a security-check for official fluentbit images and it founds a lot of CVEs (including criticals). See the example
I'm not sure it's a correct place to address the issue. If not, please tell me where I should create a bug-report.
To Reproduce
Install the vulnerability scanner trivy like described here https://aquasecurity.github.io/trivy/v0.17.0/installation/ . Then run it as
Expected behavior
There are no CVEs, at least critical ones.
Your Environment
How did you install fluent operator?
helm
What happened?
My CI/CD pipeline is broken because security-check fails. But actually the question isn't about pipeline, but about CVEs I didn't expect to see here.
Your Error Log
Additional context
No response
The text was updated successfully, but these errors were encountered: