Skip to content

Conversation

@jupyterhub-bot
Copy link
Collaborator

A rebuild of quay.io/jupyterhub/k8s-secret-sync has been found to influence the detected vulnerabilities! This PR will trigger a rebuild because it has updated a comment in the Dockerfile.

About

This scan for known vulnerabilities has been made by aquasecurity/trivy. Trivy was configured to filter the vulnerabilities with the following settings:

  • ignore-unfixed: true

Before

Before trying to rebuild the image, the following vulnerabilities was detected in quay.io/jupyterhub/k8s-secret-sync:4.2.1-0.dev.git.7122.heb35682a.

Target Vuln. ID Package Name Installed v. Fixed v.
alpine CVE-2025-9230 libcrypto3 3.5.1-r0 3.5.4-r0
alpine CVE-2025-9230 libssl3 3.5.1-r0 3.5.4-r0
alpine CVE-2025-9231 libcrypto3 3.5.1-r0 3.5.4-r0
alpine CVE-2025-9231 libssl3 3.5.1-r0 3.5.4-r0
alpine CVE-2025-9232 libcrypto3 3.5.1-r0 3.5.4-r0
alpine CVE-2025-9232 libssl3 3.5.1-r0 3.5.4-r0

After

Target Vuln. ID Package Name Installed v. Fixed v.
alpine CVE-2025-9230 libcrypto3 3.5.1-r0 3.5.4-r0
alpine CVE-2025-9230 libssl3 3.5.1-r0 3.5.4-r0
alpine CVE-2025-9231 libcrypto3 3.5.1-r0 3.5.4-r0
alpine CVE-2025-9231 libssl3 3.5.1-r0 3.5.4-r0
alpine CVE-2025-9232 libcrypto3 3.5.1-r0 3.5.4-r0
alpine CVE-2025-9232 libssl3 3.5.1-r0 3.5.4-r0
python-pkg CVE-2025-50181 urllib3 2.3.0 2.5.0
python-pkg CVE-2025-50182 urllib3 2.3.0 2.5.0

@jupyterhub-bot jupyterhub-bot added the image:rebuild-to-patch-vuln Image rebuild to patch a known external vulnerability label Oct 6, 2025
@manics manics merged commit e6ea6d8 into main Oct 6, 2025
14 of 16 checks passed
@manics manics deleted the vuln-scan-secret-sync branch October 6, 2025 10:22
consideRatio pushed a commit to jupyterhub/helm-chart that referenced this pull request Oct 6, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

image:rebuild-to-patch-vuln Image rebuild to patch a known external vulnerability

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants