Skip to content

Update kubectl version in crd.Dockerfile to avoid critival CVE CVE-2025-68121 #2048

Description

@sascha-krug

What steps did you take and what happened:
We are prescanning images we are using with trivy. Version 1.6.0 of registry.k8s.io/csi-secrets-store/driver-crds shows a critical CVE: CVE-2025-68121

What did you expect to happen:
no critical CVE's after trivy (or any other vuln scanner)

Anything else you would like to add:
this can be fixed by bumping the kubectl version in file crd.Dockerfile from v1.34.8 to at least v1.36.2

Metadata

Metadata

Assignees

No one assigned

    Labels

    kind/bugCategorizes issue or PR as related to a bug.needs-triageIndicates an issue or PR lacks a `triage/foo` label and requires one.

    Type

    No type

    Projects

    Status
    Subprojects - Needs Triage

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions