j6s / mailcow-exporter

MIT License
58 stars 12 forks source link

[CVE] Fix vulnerabilities by updating alpine #7

Closed AlexanderBabel closed 2 years ago

AlexanderBabel commented 2 years ago

Hello @j6s,

First of all, thanks for providing this fantastic open-source project. I use it myself with the Grafana dashboard.

The vulnerability scanner from armosec found 14 vulnerabilities in your image. They originate from an outdated version of alpine.

These vulnerabilities are related to: apk-tools, openssl and busybox

Found vulnerabilities (selection): CVE-2021-36159, CVE-2021-3711, CVE-2021-42378

I would really appreciate if you could merge the PR and create a new Docker tag as soon as you have time for it.

j6s commented 2 years ago

Interesting, thank you for bringing this to my attention - I would have missed it.

I am unsure if the image will autobuild but I'll trigger a build & push of the image if it doesn't

j6s commented 2 years ago

The latest and 1.3.2 images now contain your changes to the base image