Skip to content

Are the CVE fixes in v2.0.0-rc.3 applicable to flux v0.38.3 #3885

Closed Answered by stefanprodan
adamshawvipps asked this question in General
Discussion options

You must be logged in to vote

Those CVEs are not of Flux they come from Docker which we depend on. You should be updating Flux every time we do a release, if you want less CVEs.

If you're using Flux v0.38.3 than the Flux images on your cluster are affected by tones of CVEs.

Here is source-controller from Flux v0.38.3

$ trivy image ghcr.io/fluxcd/source-controller:v0.33.0

ghcr.io/fluxcd/source-controller:v0.33.0 (alpine 3.16.3)

Total: 12 (UNKNOWN: 0, LOW: 0, MEDIUM: 4, HIGH: 8, CRITICAL: 0)

┌──────────────┬───────────────┬──────────┬───────────────────┬───────────────┬────────────────────────────────────────────────────────────┐
│   Library    │ Vulnerability │ Severity │ Installed Version │ Fixed Version │         …

Replies: 3 comments 1 reply

Comment options

You must be logged in to vote
1 reply
@hiddeco
Comment options

Answer selected by adamshawvipps
Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
0 replies
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
3 participants