jupyterhub / zero-to-jupyterhub-k8s

Helm Chart & Documentation for deploying JupyterHub on Kubernetes
https://zero-to-jupyterhub.readthedocs.io
Other
1.56k stars 799 forks source link

Vulnerability patch in hub #3447

Closed jupyterhub-bot closed 4 months ago

jupyterhub-bot commented 4 months ago

A rebuild of quay.io/jupyterhub/k8s-hub has been found to influence the detected vulnerabilities! This PR will trigger a rebuild because it has updated a comment in the Dockerfile.

About

This scan for known vulnerabilities has been made by aquasecurity/trivy. Trivy was configured to filter the vulnerabilities with the following settings:

Before

Before trying to rebuild the image, the following vulnerabilities was detected in quay.io/jupyterhub/k8s-hub:4.0.0-0.dev.git.6647.haeee7f4d.

Target Vuln. ID Package Name Installed v. Fixed v.
debian CVE-2020-22218 libssh2-1 1.9.0-2 1.9.0-2+deb11u1
debian CVE-2024-0553 libgnutls30 3.7.1-5+deb11u4 3.7.1-5+deb11u5
debian CVE-2024-0567 libgnutls30 3.7.1-5+deb11u4 3.7.1-5+deb11u5
debian CVE-2024-2398 curl 7.74.0-1.3+deb11u11 7.74.0-1.3+deb11u12
debian CVE-2024-2398 libcurl3-gnutls 7.74.0-1.3+deb11u11 7.74.0-1.3+deb11u12
debian CVE-2024-2398 libcurl4 7.74.0-1.3+deb11u11 7.74.0-1.3+deb11u12

After

Target Vuln. ID Package Name Installed v. Fixed v.