Closed dpericaxon closed 1 year ago
We've already updated the alpine to 3.17.
Can you run these on the latest image? Ex: master-74d33df ?
If so we can release 1.14.2 with this new alpine i guess..
@alanprot I could do that but I'm worried if those were built off of master that there are a decent amount of commits since Dec 18th. Is this an invalid concern?
@dpericaxon master should be fine
@dpericaxon there is a release candidate to run against now: https://github.com/cortexproject/cortex/releases/tag/v1.15.0-rc.0
closing as v1.15.0 has been released. We should automate this more as there will be additional CVEs.
Summary
We ran a twistlock scan and returned the following results:
We were wondering if there is a timeline to fix these? I see an issue open for updating Go https://github.com/cortexproject/cortex/issues/5147