Skip to content

Conversation

@jupyterhub-bot
Copy link
Collaborator

A rebuild of quay.io/jupyterhub/k8s-hub has been found to influence the detected vulnerabilities! This PR will trigger a rebuild because it has updated a comment in the Dockerfile.

About

This scan for known vulnerabilities has been made by aquasecurity/trivy. Trivy was configured to filter the vulnerabilities with the following settings:

  • ignore-unfixed: true

Before

Before trying to rebuild the image, the following vulnerabilities was detected in quay.io/jupyterhub/k8s-hub:4.0.0-0.dev.git.6720.h33f21dc4.

Target Vuln. ID Package Name Installed v. Fixed v.
debian CVE-2023-25652 git 1:2.39.2-1.1 1:2.39.5-0+deb12u1
debian CVE-2023-25652 git-man 1:2.39.2-1.1 1:2.39.5-0+deb12u1
debian CVE-2023-25815 git 1:2.39.2-1.1 1:2.39.5-0+deb12u1
debian CVE-2023-25815 git-man 1:2.39.2-1.1 1:2.39.5-0+deb12u1
debian CVE-2023-29007 git 1:2.39.2-1.1 1:2.39.5-0+deb12u1
debian CVE-2023-29007 git-man 1:2.39.2-1.1 1:2.39.5-0+deb12u1
debian CVE-2024-32002 git 1:2.39.2-1.1 1:2.39.5-0+deb12u1
debian CVE-2024-32002 git-man 1:2.39.2-1.1 1:2.39.5-0+deb12u1
debian CVE-2024-32004 git 1:2.39.2-1.1 1:2.39.5-0+deb12u1
debian CVE-2024-32004 git-man 1:2.39.2-1.1 1:2.39.5-0+deb12u1
debian CVE-2024-32020 git 1:2.39.2-1.1 1:2.39.5-0+deb12u1
debian CVE-2024-32020 git-man 1:2.39.2-1.1 1:2.39.5-0+deb12u1
debian CVE-2024-32021 git 1:2.39.2-1.1 1:2.39.5-0+deb12u1
debian CVE-2024-32021 git-man 1:2.39.2-1.1 1:2.39.5-0+deb12u1
debian CVE-2024-32465 git 1:2.39.2-1.1 1:2.39.5-0+deb12u1
debian CVE-2024-32465 git-man 1:2.39.2-1.1 1:2.39.5-0+deb12u1
node-pkg CVE-2024-38999 requirejs 2.3.6 2.3.7
python-pkg CVE-2024-6345 setuptools 65.5.1 70.0.0
python-pkg GHSA-h4gh-qq45-vh27 cryptography 43.0.0 43.0.1

After

Target Vuln. ID Package Name Installed v. Fixed v.
node-pkg CVE-2024-38999 requirejs 2.3.6 2.3.7
python-pkg CVE-2024-6345 setuptools 65.5.1 70.0.0
python-pkg GHSA-h4gh-qq45-vh27 cryptography 43.0.0 43.0.1

@jupyterhub-bot jupyterhub-bot added the image:rebuild-to-patch-vuln Image rebuild to patch a known external vulnerability label Sep 16, 2024
@manics manics merged commit 77134f1 into main Sep 16, 2024
13 checks passed
@manics manics deleted the vuln-scan-hub branch September 16, 2024 09:31
consideRatio pushed a commit to jupyterhub/helm-chart that referenced this pull request Sep 16, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

image:rebuild-to-patch-vuln Image rebuild to patch a known external vulnerability

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants