Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Deprecated tag for nginxinc/nginx-unprivileged (incl. CVE-2023-4863) #10746

Closed
mrmatimba opened this issue Sep 29, 2023 · 0 comments · Fixed by #10754
Closed

Deprecated tag for nginxinc/nginx-unprivileged (incl. CVE-2023-4863) #10746

mrmatimba opened this issue Sep 29, 2023 · 0 comments · Fixed by #10754

Comments

@mrmatimba
Copy link

Describe the bug
The Loki helm charts points to an old tag of nginxinc/nginx-unprivileged. Please update it and solve CVE-2023-4863

To Reproduce
Steps to reproduce the behavior:

  1. Deploy Loki chart version 5.23.1
  2. Run Trivy vulnerability scan
  3. nginxinc/nginx-unprivileged:1.23-alpine is reported with several vulnerabilities (incl. CVE-2023-4863)

Expected behavior
Latest version of nginxinc/nginx-unprivileged is used and CVEs are solved.

Environment:

  • Infrastructure: Azure Kubernetes Service
  • Deployment tool: helm

Screenshots, Promtail config, or terminal output
n/a

MichelHollands pushed a commit that referenced this issue Oct 9, 2023
**What this PR does / why we need it**:

**Which issue(s) this PR fixes**:
Fixes #10746 

**Special notes for your reviewer**:

**Checklist**
- [x] Reviewed the
[`CONTRIBUTING.md`](https://github.com/grafana/loki/blob/main/CONTRIBUTING.md)
guide (**required**)
- [ ] Documentation added
- [ ] Tests updated
- [x] `CHANGELOG.md` updated
- [ ] If the change is worth mentioning in the release notes, add
`add-to-release-notes` label
- [ ] Changes that require user attention or interaction to upgrade are
documented in `docs/sources/setup/upgrade/_index.md`
- [x] For Helm chart changes bump the Helm chart version in
`production/helm/loki/Chart.yaml` and update
`production/helm/loki/CHANGELOG.md` and
`production/helm/loki/README.md`. [Example
PR](d10549e)
rhnasc pushed a commit to inloco/loki that referenced this issue Apr 12, 2024
**What this PR does / why we need it**:

**Which issue(s) this PR fixes**:
Fixes grafana#10746 

**Special notes for your reviewer**:

**Checklist**
- [x] Reviewed the
[`CONTRIBUTING.md`](https://github.com/grafana/loki/blob/main/CONTRIBUTING.md)
guide (**required**)
- [ ] Documentation added
- [ ] Tests updated
- [x] `CHANGELOG.md` updated
- [ ] If the change is worth mentioning in the release notes, add
`add-to-release-notes` label
- [ ] Changes that require user attention or interaction to upgrade are
documented in `docs/sources/setup/upgrade/_index.md`
- [x] For Helm chart changes bump the Helm chart version in
`production/helm/loki/Chart.yaml` and update
`production/helm/loki/CHANGELOG.md` and
`production/helm/loki/README.md`. [Example
PR](grafana@d10549e)
mraboosk pushed a commit to mraboosk/loki that referenced this issue Oct 7, 2024
**What this PR does / why we need it**:

**Which issue(s) this PR fixes**:
Fixes grafana#10746 

**Special notes for your reviewer**:

**Checklist**
- [x] Reviewed the
[`CONTRIBUTING.md`](https://github.com/grafana/loki/blob/main/CONTRIBUTING.md)
guide (**required**)
- [ ] Documentation added
- [ ] Tests updated
- [x] `CHANGELOG.md` updated
- [ ] If the change is worth mentioning in the release notes, add
`add-to-release-notes` label
- [ ] Changes that require user attention or interaction to upgrade are
documented in `docs/sources/setup/upgrade/_index.md`
- [x] For Helm chart changes bump the Helm chart version in
`production/helm/loki/Chart.yaml` and update
`production/helm/loki/CHANGELOG.md` and
`production/helm/loki/README.md`. [Example
PR](grafana@2cef71e)
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging a pull request may close this issue.

1 participant