fluent / fluent-bit-docker-image

Docker image for Fluent Bit
https://hub.docker.com/r/fluent/fluent-bit/
Apache License 2.0
67 stars 75 forks source link

Multiple CVEs when installing bin/fluent-bit #43

Closed SvenScheurer closed 2 years ago

SvenScheurer commented 2 years ago

Dear team,

switching to a Debian bullseye base image, we are using the 1.8.10 stable fluent-bit Dockerfile to create our FluentBit image.

We've now noticed 25 CVEs related to the installation of the fluent-bit bin (RUN install bin/fluent-bit /fluent-bit/bin/) Namely, the following components are affected (mostly since old versions used)

Is there a backward-compatible way to update those libs from the Dockerfile? And are you planning on updating those libs with the fluent-bit installation for security reasons?

SvenScheurer commented 2 years ago

There was an issue with the security scanner used properly resolving the image layers - closing as invalid