skupperproject / skupper-router

An application-layer router for Skupper networks
https://skupper.io
Apache License 2.0
14 stars 18 forks source link

Remove gnutls and all libraries that depend on it #1477

Closed ganeshmurthy closed 4 months ago

ganeshmurthy commented 4 months ago

gnutls has been involved in more that one CVE and skupper-router does not use it. Remove gnutls and its dependencies from the skupper-router container image so any future CVEs against gnutls does not affect the skupper-router container image.

For example, this CVE - https://access.redhat.com/errata/RHSA-2024:1879