openebs / lvm-localpv

Dynamically provision Stateful Persistent Node-Local Volumes & Filesystems for Kubernetes that is integrated with a backend LVM2 data storage stack.
Apache License 2.0
235 stars 92 forks source link

Alpine version used in images requires update #262

Closed emiran-orange closed 9 months ago

emiran-orange commented 9 months ago

Describe the problem/challenge you have Alpine 3.14.8 contains vulnerabilities related to CVE-2022-4450, CVE-2023-0215, CVE-2023-0286, CVE-2023-0464. It seems that these vulnerabilities cannot be exploited as the binary only expose insecured metrics endpoint but, you know, security right ?...

Describe the solution you'd like An update of the Alpine version used

Anything else you would like to add: None that I think of

Environment: