jupyterhub / zero-to-jupyterhub-k8s

Helm Chart & Documentation for deploying JupyterHub on Kubernetes
https://zero-to-jupyterhub.readthedocs.io
Other
1.56k stars 799 forks source link

Vulnerability patch in secret-sync #3549

Closed jupyterhub-bot closed 1 month ago

jupyterhub-bot commented 1 month ago

A rebuild of quay.io/jupyterhub/k8s-secret-sync has been found to influence the detected vulnerabilities! This PR will trigger a rebuild because it has updated a comment in the Dockerfile.

About

This scan for known vulnerabilities has been made by aquasecurity/trivy. Trivy was configured to filter the vulnerabilities with the following settings:

Before

Before trying to rebuild the image, the following vulnerabilities was detected in quay.io/jupyterhub/k8s-secret-sync:4.0.0-beta.4.

Target Vuln. ID Package Name Installed v. Fixed v.

After

Target Vuln. ID Package Name Installed v. Fixed v.
alpine CVE-2024-9143 libcrypto3 3.3.2-r0 3.3.2-r1
alpine CVE-2024-9143 libssl3 3.3.2-r0 3.3.2-r1