What happened?
CVE image scan lists 3 high severity CVEs.
| IMAGE |
SEVERITY |
IMPACTED PACKAGE |
FIXED VERSIONS |
CVEs |
| ghcr.io/mellanox/nic-feature-discovery:v0.0.1 |
High |
github.com/golang/go |
1.20.12,1.21.5 |
CVE-2023-45285 |
| ghcr.io/mellanox/nic-feature-discovery:v0.0.1 |
High |
github.com/golang/go |
1.20.9,1.21.2 |
CVE-2023-39323 |
| ghcr.io/mellanox/nic-feature-discovery:v0.0.1 |
High |
github.com/golang/go |
1.20.11,1.20.12,1.21.4,1.21.5 |
CVE-2023-45283 |
What did you expect to happen?
No critical or high severity CVEs.
What are the minimal steps needed to reproduce the bug?
Anything else we need to know?
CVE Scanner: JFrog
Component Versions
v0.0.1
Logs
NVIDIA NIC Feature Discovery Logs (use kubectl logs $PODNAME)