flatcar / nebraska

Update monitor & manager for applications using the Omaha protocol, optimized for Flatcar Container Linux.
https://www.flatcar.org/docs/latest/nebraska
Apache License 2.0
171 stars 43 forks source link

Security concerns #630

Open tijmenvandenbrink opened 1 year ago

tijmenvandenbrink commented 1 year ago

Description

When scanning the Nebraska repo we're seeing a lot of vulnerabilties.

Impact

Several critical vulnerabilities that - if used by Nebraska - could potentially make Nebraska vulnerable

Environment and steps to reproduce

Scan the repo with Trivy and you'll get a lot of critical vulnerabilities:

trivy repo --vuln-type library https://github.com/kinvolk/nebraska.git

joaquimrocha commented 1 year ago

Thanks @tijmenvandenbrink , we'll look into it.