Comments (6)
Yeah a fix on the updater is in progress. Should be fixed soon
from distroless.
the vulnerability is acutally contained in libuuid1
which is indeed referenced in the distroless images: https://github.com/search?q=repo%3AGoogleContainerTools%2Fdistroless%20libuuid1&type=code
from distroless.
Is there any plan to fix the vulnerability?
from distroless.
Pretty sure we don't include util-linux in our builds. Sounds like maybe its being added on after distroless? But feel free to reopen if you can confirm it's coming from distroless.
from distroless.
Is there any plan to fix the vulnerability?
We had same warning on distroless/java17-debian12, and it suggests to upgrade to 2.38.1-5+deb12u1
from distroless.
We see the same warning via a Trivy scan using an unchanged distroless image java21 image.
Steps to reproduce:
- Install trivy: https://aquasecurity.github.io/trivy/v0.18.3/installation/
docker pull gcr.io/distroless/java21-debian12:latest
trivy image gcr.io/distroless/java21-debian12:latest
from distroless.
Related Issues (20)
- Golang mime.TypeByExtension(".tif") Returns Empty in Debian 12 Distroless Images HOT 1
- libc6 CVE patches - CVE-2023-6246 and CVE-2023-6779 HOT 4
- openjdk-17 CVE patches - CVE-2024-20918, CVE-2024-20932 and CVE-2024-20952 HOT 3
- How to add msttcorefonts to the image HOT 4
- Find glibc version used in base-nossl-debian12:nonroot HOT 2
- CVE-2023-52425 HOT 2
- MODULE_NOT_FOUND when starting any node application based on latest distroless images HOT 6
- CVE-2023-24329 HOT 1
- Using official Python base images and packaging into distroless later on HOT 1
- Should be based on Alpine HOT 1
- Reduce nodejs image size by removing /nodejs/include directory HOT 2
- Getting /lib/x86_64-linux-gnu/libc.so.6: version `GLIBC_2.32' not found error when using distroless base HOT 1
- nuxt.js throws Error: Cannot find module '/app/node' HOT 4
- Merge /var/lib/dpkg/status.d/* HOT 1
- `static` tag is based on Debian 11 HOT 2
- use of non existing index.bzl file HOT 1
- CVE-2024-2961 HOT 3
- Docker image with distroless as a base image is throwing error while deploying to AWS EKS HOT 3
- How to install git on a distroless image? HOT 3
Recommend Projects
-
React
A declarative, efficient, and flexible JavaScript library for building user interfaces.
-
Vue.js
🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.
-
Typescript
TypeScript is a superset of JavaScript that compiles to clean JavaScript output.
-
TensorFlow
An Open Source Machine Learning Framework for Everyone
-
Django
The Web framework for perfectionists with deadlines.
-
Laravel
A PHP framework for web artisans
-
D3
Bring data to life with SVG, Canvas and HTML. 📊📈🎉
-
Recommend Topics
-
javascript
JavaScript (JS) is a lightweight interpreted programming language with first-class functions.
-
web
Some thing interesting about web. New door for the world.
-
server
A server is a program made to process requests and deliver data to clients.
-
Machine learning
Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.
-
Visualization
Some thing interesting about visualization, use data art
-
Game
Some thing interesting about game, make everyone happy.
Recommend Org
-
Facebook
We are working to build community through open source technology. NB: members must have two-factor auth.
-
Microsoft
Open source projects and samples from Microsoft.
-
Google
Google ❤️ Open Source for everyone.
-
Alibaba
Alibaba Open Source for everyone
-
D3
Data-Driven Documents codes.
-
Tencent
China tencent open source team.
from distroless.