-
Notifications
You must be signed in to change notification settings - Fork 59
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
CVEs found in latest ghcr.io/vroom-project/vroom-docker:v1.14.0 #83
Comments
Thanks for reporting, do you have any suggestion on how to fix this? |
It looks like most of these vulnerabilities are debian packages so looking at your dockerfile they maybe come from Given that all these CVEs are 2024 and you haven't released since Jan I would imagine doing another release of vroom perhaps By releasing again you're grabbing a more up to date node image it's looking like the latest node 20 bookworm has no HIGH or CRITICAL vulnerabilities in it. I've just built a fresh image of vroom-docker getting:
so a rerelease would be a massive improvement |
Additionally do you plan to release vroom-docker on a regular basis? Otherwise we may go ahead and release it ourselves on a more regular basis for our security needs |
Releases for |
I guess most of those are now fixed after the upgrade in #88, shall we close here? |
We should probably release a new version of vroom-docker for these CVE fixes? I think you only release when there's a new version of vroom though right? |
Total: 24 (HIGH: 24, CRITICAL: 0)
The text was updated successfully, but these errors were encountered: