Skip to content

[3.4] Security: use distroless base image to address critical Vulnerabilities#15017

Merged
ahrtr merged 1 commit intoetcd-io:release-3.4from
ahrtr:use_distroless_3.4_20221219
Dec 19, 2022
Merged

[3.4] Security: use distroless base image to address critical Vulnerabilities#15017
ahrtr merged 1 commit intoetcd-io:release-3.4from
ahrtr:use_distroless_3.4_20221219

Conversation

@ahrtr
Copy link
Copy Markdown
Member

@ahrtr ahrtr commented Dec 19, 2022

Command:

trivy image --severity CRITICAL gcr.io/etcd-development/etcd:v3.4.22 

Report:

Screen Shot 2022-12-19 at 08 07 18

Signed-off-by: Benjamin Wang [email protected]

Please read https://github.com/etcd-io/etcd/blob/main/CONTRIBUTING.md#contribution-flow.

cc @mitake @ptabor @serathius @spzala

Command:
trivy image --severity CRITICAL gcr.io/etcd-development/etcd:v3.4.22  -f json -o 3.4.22_image_critical.json

Signed-off-by: Benjamin Wang <[email protected]>
@ahrtr ahrtr added area/security priority/important-soon Must be staffed and worked on either currently, or very soon, ideally in time for the next release. labels Dec 19, 2022
Copy link
Copy Markdown
Member

@fuweid fuweid left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM(non-binding)

@ahrtr ahrtr merged commit f318a39 into etcd-io:release-3.4 Dec 19, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area/security priority/important-soon Must be staffed and worked on either currently, or very soon, ideally in time for the next release.

Development

Successfully merging this pull request may close these issues.

3 participants