kubesphere / helm-charts

Source & Repo of https://charts.kubesphere.io/main & https://charts.kubesphere.io/test
97 stars 175 forks source link

security vulnerabilities for juice package #341

Open calvinyv opened 9 months ago

calvinyv commented 9 months ago

As attach

iShot_2023-11-24_16 26 23
calvinyv commented 9 months ago

@zwwhdls

zwwhdls commented 9 months ago

This image is from quay, not maintained by us. Also, did schema v1 manifest not supported by trivy means security vulnerabilities? My understanding is that trivy does not support scanning images with schema v1.

zheng1 commented 9 months ago

Can you upgrade this image? I think the latest version is v2.11.0 and has solved this problem, https://kubernetes-csi.github.io/docs/livenessprobe.html#status-and-releases.