Skip to content

Critical Vulnerability CVE-2024-41110 in v26.0.1 of docker included in k9s #2938

@sarg3nt

Description

@sarg3nt

We are building k9s into a go-dev-container and trivy security scanning is detecting the above mentioned critical vulnerability in k9s. See screenshot below.

A few thoughts.

  1. You have a lot of PRs from dependabot waiting to be merged. Any reason why?
  2. Recommend turning on trivy scanning.
  3. Recommend running your repo through https://app.stepsecurity.io/securerepo This tool is recommended by the ossf scorecard. Another security tool you can look into if you like.

Also CVE-2024-6257 , see second screenshot below.

image
Also
image

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't working

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions