-
Notifications
You must be signed in to change notification settings - Fork 5.7k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Remove the kubernetes version dependency to reduce the risk of vulnerabilities #12288
Comments
That vulnerability applies to <= 1.22.0. We're currently on 1.24.2. |
Whether to consider not introducing kubernetes's own dependencies, and complete the requirements by referencing other components |
Sorry, could you rephrase your question? |
updated @jessesuen |
Remove the kubernetes scheme module. Do you have any good ideas to discuss? I have researched for several days, but I can't find a better solution @crenshaw-dev @jessesuen |
Security scanners also report ArgoCD containing CVE-2022-3294 which is a a k8s package vul in v1.24.2, fixed in 1.24.8 or 1.25.4. Bumping to 1.24.8 would at least check the security scanner's box. |
The currently used kubernetes version has a vulnerability of CVE-2020-8554, whether to consider refactoring the gitops-engine module, upgrade the kubernetes version to 1.26.x or above, and use new features to complete some required functions
The text was updated successfully, but these errors were encountered: