open-policy-agent / kube-mgmt

Sidecar for managing OPA instances in Kubernetes.
Apache License 2.0
235 stars 105 forks source link

High Severity Vulnerability Found in Snyk Scan in v8.5.4 or below #243

Closed mlajkim closed 7 months ago

mlajkim commented 7 months ago

Background

I've found that the latest kube-mgmt v8.5.4 has the following high-severity vulnerability: https://security.snyk.io/vuln/SNYK-GOLANG-GOPKGINYAMLV3-2952714

This can be simply fixed by following: image

mlajkim commented 7 months ago

I've internally run snyk check for the 8.5.5 version and the vulnerability has been fixed.

https://github.com/open-policy-agent/kube-mgmt/releases/tag/8.5.5