-
Notifications
You must be signed in to change notification settings - Fork 8.3k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Nginx-ingress-controller 1.6.4 is flagged as critical vulnerable image #9748
Comments
We are already on x/net v0.8 Line 104 in 2324ad0
/remove-kind bug We are updaring go to v1.20 in the next release of the controller |
We're working on a new release to upgrade to golang 1.20 and alpine 3.17.2, there are several steps involved in that, and there are issues with the CI currently. We have to first upgrade our build and testing image to golang 1.20, upgrade the nginx base container image and update the ingress-controller container go.mod; then, we can release an updated version. |
/kind feature |
@strongjz: The label(s) In response to this:
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes/test-infra repository. |
I am consuming the contents directly from path ingress-nginx/charts/ingress-nginx (https://github.com/kubernetes/ingress-nginx/tree/main/charts/ingress-nginx) and the scans show golang.org/x/net v0.5.0 is detected. No Specific reference to go,mod file were made. |
It will be updated in the next release. Please be patient https://github.com/kubernetes/ingress-nginx/blob/main/go.mod#L104 |
Sure. Thanks for the update |
@strongjz: Closing this issue. In response to this:
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes/test-infra repository. |
What scanner and version reported the CVE?
Internal Tool
What CVE was reported in the scanner findings?
GO (Go) Security Update for golang.org/x/net (GHSA-vvpx-j8f3-3w6h)
What versions of the controller did you test with?
Nginx-ingress-controller 1.6.4
Please provider other details that will help us determine the severity of the issue
GO (Go) Security Update for golang.org/x/net (GHSA-vvpx-j8f3-3w6h)
GHSA-vvpx-j8f3-3w6h
The text was updated successfully, but these errors were encountered: