You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
When I pull and build from the 106.1 opentelemetry-collector-contrib image, the Docker Scout scan flags a "9.9" critical issue (CVE-2024-41110) against usage of github.com/docker/docker v26.1.4
Searching the 106.1 codebase, it appears that github.com/docker/docker v26.1.4 version is referenced ~45 times across the codebase.
Component(s)
Multiple
What happened?
Docker Scout scan fails with a critical CVE.
Description
When I pull and build from the 106.1 opentelemetry-collector-contrib image, the Docker Scout scan flags a "9.9" critical issue (CVE-2024-41110) against usage of
github.com/docker/docker v26.1.4
Searching the 106.1 codebase, it appears that
github.com/docker/docker v26.1.4
version is referenced ~45 times across the codebase.According to the scan, this CVE is addressed in github.com/docker/docker v26.1.5.
See:
Steps to Reproduce
Dockerfile
Expected Result
successful scan
Actual Result
Collector version
v0.106.1
Environment information
Scanning using Docker Desktop 4.33.1
OpenTelemetry Collector configuration
No response
Log output
No response
Additional context
No response
The text was updated successfully, but these errors were encountered: