-
Notifications
You must be signed in to change notification settings - Fork 1.6k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Docker image gcr.io/ml-pipeline/api-server:0.1.16 has many security issues #1545
Comments
This version is pretty old. Can you please try upgrading? |
@JavaDerek |
@IronPan this might be a good place for us to start |
@IronPan I can't comment on what we do, but I've been able to verify that Clair (https://github.com/coreos/clair) would give you the above findings. Also, @Ark-kun - upgrading produced a different, smaller list of vulnerabilities, but unfortunately still vulnerabilities. |
This reduces the image size, reduces the attack surface and avoids security vulnerabilities. Fixes kubeflow#1545
* Backend - Starting the container build from scratch This reduces the image size, reduces the attack surface and avoids security vulnerabilities. Fixes #1545 * Starting building other controller images from scratch
Security scanning of the latest api-server Docker image in the repo indicates the following CVE's...
CVE-2017-14062
CVE-2017-8804
CVE-2018-6485
CVE-2018-6551
CVE-2018-1000001
CVE-2019-9169
CVE-2017-12424
CVE-2018-15686
CVE-2016-2779
CVE-2018-12886
The text was updated successfully, but these errors were encountered: