-
Notifications
You must be signed in to change notification settings - Fork 162
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Address CVE-2024-41110 #1728
Comments
This was fixed in lifecycle v0.20.1 (kpack currently uses v0.17.2) but they noted that it is "Non-impactful as the lifecycle uses only the docker client library" : buildpacks/lifecycle#1391 (comment) |
Thanks @diarmuidie! Is the lifecycle dependency the only source of the |
ya this appears to only affect docker engine itself, so we should be okay |
Thanks @tomkennedy513. I suspect we can close this ticket out in that case (or leave it open until the lifecycle upgrade is applied). |
An upgrade of the Docker Golang package is needed to address: GHSA-v23v-6jw2-98fq
The text was updated successfully, but these errors were encountered: