Skip to content

High severity CVEs in latest released image ghcr.io/mellanox/nic-feature-discovery:v0.0.1 #24

@gseidlerhpe

Description

@gseidlerhpe

What happened?

CVE image scan lists 3 high severity CVEs.

IMAGE SEVERITY IMPACTED PACKAGE FIXED VERSIONS CVEs
ghcr.io/mellanox/nic-feature-discovery:v0.0.1 High github.com/golang/go 1.20.12,1.21.5 CVE-2023-45285
ghcr.io/mellanox/nic-feature-discovery:v0.0.1 High github.com/golang/go 1.20.9,1.21.2 CVE-2023-39323
ghcr.io/mellanox/nic-feature-discovery:v0.0.1 High github.com/golang/go 1.20.11,1.20.12,1.21.4,1.21.5 CVE-2023-45283

What did you expect to happen?

No critical or high severity CVEs.

What are the minimal steps needed to reproduce the bug?

Anything else we need to know?

CVE Scanner: JFrog

Component Versions

v0.0.1

Logs

NVIDIA NIC Feature Discovery Logs (use kubectl logs $PODNAME)

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions