apache / apache/pulsar

[Security] v2.10.2 contains 35 fixable vulnerabilities

Open
#18,348 15 comments 0 reactions 0 assignees View on GitHub
area/security Stale type/bug
Dominant language
Java
Stars
15.3k
Forks
3.8k
Avg merge
1d 14h
Merged PRs (30d)
160

Description

### Search before asking

- [X] I searched in the [issues](https://github.com/apache/pulsar/issues) and found nothing similar.

### Version

v2.10.2

### Minimal reproduce step

look into trivy powered inspection for vulnerabilities
at artifacthub.io
https://artifacthub.io/packages/helm/apache/pulsar?modal=security-report

open details of in the latest helm chart v3.0.0 included pulsar v2.10.2 image

### What did you expect to see?

very few fixable vulnerabilities, since v2.10.2 was released just 8 days ago https://github.com/apache/pulsar/releases

### What did you see instead?

- 72 vulnerabilities have been detected in the image
- 35 of these should be fixable (most with a version bump of dependencies)

![2022-11-04_17h06_11](https://user-images.githubusercontent.com/5681880/200025536-a6808fb3-2f4a-4e31-92ba-9c5f61ebe4f1.png)

![2022-11-04_17h03_17](https://user-images.githubusercontent.com/5681880/200025573-871fc438-6d24-4788-90c9-cce8bf7ab477.png)

### Anything else?

- this is related to
https://github.com/apache/pulsar/issues/18338
- this is a follow up of
https://github.com/apache/pulsar/issues/18041
- this is part of
https://github.com/apache/pulsar-helm-chart/issues/334

### Are you willing to submit a PR?

- [ ] I'm willing to submit a PR!

Contributor guide

Open the contributing guide

Research direction

Start with the Trivy security report for the v3.0.0 Helm chart and its included Pulsar v2.10.2 image, then review the related issues 18338 and 18041 and apache/pulsar-helm-chart issue 334. Done means addressing the reported fixable vulnerabilities and confirming the resulting image report shows substantially fewer vulnerabilities.

Written by the indexing model from the issue text.

Assessment

Tech stack
docker, helm, java
Domain
devops, infrastructure, security
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.