Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Critical and High Severity in alpine image in google/cloud-sdk/492.0.0-alpine #472

Open
nmeena-suki opened this issue Sep 11, 2024 · 4 comments

Comments

@nmeena-suki
Copy link

nmeena-suki commented Sep 11, 2024

The alpine version of this image seems to be vulnerable to GHSA-v23v-6jw2-98fq
You need to update your docker static source version
Image: https://hub.docker.com/layers/google/cloud-sdk/492.0.0-alpine/images/sha256-201db51115dc28aea998b5caf581233733957b289169acd1d54b7102a41d4bab?context=explore

There are also other high vulnerabilites in cryptography package and the fix is available
GHSA-3ww4-gg4f-jr7f
GHSA-6vqw-3v5j-54x4

When can we expect an upgrade

@nmeena-suki
Copy link
Author

There are 20 Vul, out of which these are fixable

Screenshot 2024-09-11 at 1 37 00 PM

@young-mmfm
Copy link

google/cloud-sdk/493.0.0-alpine also has security issues:
Screenshot 2024-09-23 at 11 59 41 AM

493.0 went back to Alpine 3.19 from Alpine 3.20. Alpine 3.20.3 currently has no known vulnerabilities: https://hub.docker.com/layers/library/alpine/3.20.3/images/sha256-33735bd63cf84d7e388d9f6d297d348c523c044410f553bd878c6d7829612735?context=explore.

Wondering if it's possible to upgrade to Alpine 3.20.3? 🙏 Thank you!

@young-mmfm
Copy link

Correction: even when upgrading to Alpine 3.20.3, there seem to be vulnerabilities specifically in py3-openssl and the google cloud CLI:
Screenshot 2024-09-23 at 1 53 12 PM

@anindyatahsin
Copy link
Contributor

anindyatahsin commented Oct 13, 2024

Alpine version update (to version 3.20) is currently blocked on the gsutil component, which is not compliant with the python 3.12 version. This is because python 3.12 is the default python version that comes with alpine version 3.20. A fix with alpine 3.20 and python 3.11 manually installed is available in the alpine-upgrade branch and currently being tested.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants