k3d-io / k3d

Little helper to run CNCF's k3s in Docker
https://k3d.io/
MIT License
5.48k stars 462 forks source link

[BUG] Several vulnerabilites found within the `k3d-proxy` docker image. #1472

Open jackson-chris opened 4 months ago

jackson-chris commented 4 months ago

What did you do

Installed k3d version 5.7.2 without any issues, then performed security scans using JFROG Xray on the images and found several high and critical vulnerabilities listed in attached text document.

What did you expect to happen

These vulnerabilities all have released fixes and should be updated to remediate the CVEs. Adoption of k3d is limited when a high amount of CVEs are present and show up on consumers security scans.

Screenshots or terminal output

See scan-results.txt

Which OS & Architecture

N/A

Which version of k3d

5.7.2

Which version of docker

N/A