Are the CVE fixes in v2.0.0-rc.3 applicable to flux v0.38.3 #3885
-
Hi there. We are on flux v0.38.3 and I am wondering if we need to upgrade to v2.0.0-rc.3 to address these CVE's or were they introduced later than v0.38.3? Thanks for your advice |
Beta Was this translation helpful? Give feedback.
Replies: 3 comments 1 reply
-
Those CVEs are not of Flux they come from Docker which we depend on. You should be updating Flux every time we do a release, if you want less CVEs. If you're using Flux v0.38.3 than the Flux images on your cluster are affected by tones of CVEs. Here is source-controller from Flux v0.38.3
|
Beta Was this translation helpful? Give feedback.
-
Thanks very much for your quick response and the good talk at Kubecon Amsterdam |
Beta Was this translation helpful? Give feedback.
-
@adamshawvipps just to clarify the 2 CVEs, I've updated the changelog to
|
Beta Was this translation helpful? Give feedback.
Those CVEs are not of Flux they come from Docker which we depend on. You should be updating Flux every time we do a release, if you want less CVEs.
If you're using Flux v0.38.3 than the Flux images on your cluster are affected by tones of CVEs.
Here is source-controller from Flux v0.38.3