I used v0.13.1, helm chartmuseum image vulnerabilities were found during trivy scan.
| LIBRARY |
FIXED VERSION |
VULNERABILITY ID |
SEVERITY |
| github.com/containerd/containerd |
v1.4.11, v1.5.7 |
CVE-2021-41103 |
HIGH |
| github.com/containerd/containerd |
v1.4.8, v1.5.4 |
CVE-2021-32760 |
MEDIUM |
| github.com/dgrijalva/jwt-go |
Unknown |
CVE-2020-26160 |
HIGH |
| github.com/docker/cli |
v20.10.9 |
CVE-2021-41092 |
HIGH |
| github.com/docker/distribution |
v2.7.0-rc.0+incompatible |
CVE-2017-11468 |
HIGH |
| github.com/opencontainers/runc |
v1.0.0-rc8.0.20190930145003-cad42f6e0932 |
CVE-2019-16884 |
HIGH |
| github.com/opencontainers/runc |
v1.0.0-rc9.0.20200122160610-2fc03cc11c77 |
CVE-2019-19921 |
HIGH |
| github.com/satori/go.uuid |
v1.2.1-0.20181016170032-d91630c85102 |
GO-2020-0018 |
UNKNOWN |
I used v0.13.1, helm chartmuseum image vulnerabilities were found during trivy scan.