grafana / alloy

OpenTelemetry Collector distribution with programmable pipelines
https://grafana.com/oss/alloy
Apache License 2.0
1.01k stars 105 forks source link

ubuntu:lunar security scanning vulns #402

Open captncraig opened 11 months ago

captncraig commented 11 months ago

This is a tracking issue for security vulnerabilities in ubuntu:lunar reported by trivy:

None of these are HIGH severity, and none seem exploitable through grafana-agent functionality. Presumably, these will be resolved in future ubuntu versions, which we will update to as soon as feasible.

github-actions[bot] commented 10 months ago

This issue has been automatically marked as stale because it has not had any activity in the past 30 days. The issue will not be closed automatically, but a label will be added to it for tracking purposes.

If the opened issue is a bug, check if newer releases have fixed the issue. If the issue is no longer relevant, please feel free to close it. Thank you for your contributions!

rfratto commented 3 months ago

Hi there :wave:

On April 9, 2024, Grafana Labs announced Grafana Alloy, the spirital successor to Grafana Agent and the final form of Grafana Agent flow mode. As a result, Grafana Agent has been deprecated and will only be receiving bug and security fixes until its end-of-life around November 1, 2025.

To make things easier for maintainers, we're in the process of migrating all issues tagged variant/flow to the Grafana Alloy repository to have a single home for tracking issues. This issue is likely something we'll want to address in both Grafana Alloy and Grafana Agent, so just because it's being moved doesn't mean we won't address the issue in Grafana Agent :)