Closed MrHohn closed 1 year ago
[APPROVALNOTIFIER] This PR is APPROVED
This pull-request has been approved by: MrHohn
The full list of commands accepted by this bot can be found here.
The pull request process is described here
Oh by the way, distroless-iptables is still bringing in the same CVEs that you tried to fix in 2.9.1, because of gorunner.
Oh by the way, distroless-iptables is still bringing in the same CVEs that you tried to fix in 2.9.1, because of gorunner.
Confirmed that is the case. Let's hold this PR and wait for a fixed distroless-iptables image. /hold
It's now already bumped to 0.2.0 but it's likely we'll need another bump for https://github.com/kubernetes/release/issues/2909 - maybe we can reuse this PR for that.
PR needs rebase.
@jingyuanliang Thanks for your recent efforts on updating the dependency. Let me close this PR for the time being and will have a new one raised when needed.
Update to use the latest iptables-distroless base image to pick up CVE fixes. Ref https://github.com/kubernetes/release/pull/2831 and https://github.com/kubernetes/release/pull/2667.
/assign@ jingyuanliang