[Security] v2.10.2 contains 35 fixable vulnerabilities
- Dominant language
- Java
- Stars
- 15.3k
- Forks
- 3.8k
- Avg merge
- 1d 14h
- Merged PRs (30d)
- 160
Description
### Search before asking
- [X] I searched in the [issues](https://github.com/apache/pulsar/issues) and found nothing similar.
### Version
v2.10.2
### Minimal reproduce step
look into trivy powered inspection for vulnerabilities
at artifacthub.io
https://artifacthub.io/packages/helm/apache/pulsar?modal=security-report
open details of in the latest helm chart v3.0.0 included pulsar v2.10.2 image
### What did you expect to see?
very few fixable vulnerabilities, since v2.10.2 was released just 8 days ago https://github.com/apache/pulsar/releases
### What did you see instead?
- 72 vulnerabilities have been detected in the image
- 35 of these should be fixable (most with a version bump of dependencies)


### Anything else?
- this is related to
https://github.com/apache/pulsar/issues/18338
- this is a follow up of
https://github.com/apache/pulsar/issues/18041
- this is part of
https://github.com/apache/pulsar-helm-chart/issues/334
### Are you willing to submit a PR?
- [ ] I'm willing to submit a PR!
Contributor guide
Research direction
Start with the Trivy security report for the v3.0.0 Helm chart and its included Pulsar v2.10.2 image, then review the related issues 18338 and 18041 and apache/pulsar-helm-chart issue 334. Done means addressing the reported fixable vulnerabilities and confirming the resulting image report shows substantially fewer vulnerabilities.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- docker, helm, java
- Domain
- devops, infrastructure, security
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 25/100