Azure / AKS

Azure Kubernetes Service
https://azure.github.io/AKS/
1.97k stars 310 forks source link

[BUG] Confidential Compute add-on for AKS images have outdated binaries #4506

Open sdx-jkataja opened 3 months ago

sdx-jkataja commented 3 months ago

Describe the bug Please provide an updated image of the acc/sgx-webhook and acc/sgx-plugin image. This is part of the Confidential Compute add-on for AKS. Grype reports acc/sgx-webhook has 8 critical and 23 high vulnerabilities while acc/sgx-plugin has 6 critical and 9 high vulnerabilities as of now.

To Reproduce Steps to reproduce the behavior:

  1. Run vulnerability scan
  2. See error

Expected behavior No Critical vulnerabilities.

Screenshots

Environment (please complete the following information):

Additional context

microsoft-github-policy-service[bot] commented 3 months ago

@agowdamsft would you be able to assist?