sorintlab / stolon

PostgreSQL cloud native High Availability and more.
https://talk.stolon.io
Apache License 2.0
4.66k stars 447 forks source link

Multiple vulnerabilities found in [Stolon:master-pg14] during JFrog scan. #885

Closed HimanshuPanwarSF closed 2 years ago

HimanshuPanwarSF commented 2 years ago

What happened: Hi, we've faced several security issues when scanning the Stolon (master-pg14) with JFrog X-Ray. There were 27 critical security issues, the rest were high, medium and low.

What you expected to happen: Expected was minimal security issues while the JFrog scan.

How to reproduce it (as minimally and precisely as possible): Just scanning Stolon:master-pg14 with JFrog Xray.

Anything else we need to know?: We request you to fix the issues as we have to move our project to the production stage.

Environment:

sgotti commented 2 years ago

@HimanshuPanwarSF As stated in the documentation the image is just an example image built after a release since we don't have time to also maintain all possible images. Just build your preferred images.