redhat-cop / redhat-cop/group-sync-operator

132 CVE's 68 Fixable !

Open
#330 4 comments 2 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
Go
Stars
132
Forks
71
PR merge metrics
No merged PRs in 30d

Description

Just deployed this operator from the operator hub that works really well, but .....
132 CVE's where 68 are Fixable, and a monster old kube-rbac-proxy image.

Any plans on getting it updated ?

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start with the deployed OperatorHub bundle and identify where the kube-rbac-proxy image is specified. Review the reported 132 CVEs and determine which 68 are fixable through an image update; done means the operator uses an updated image and a follow-up scan confirms the relevant vulnerabilities are resolved.

Written by the indexing model from the issue text.

Assessment

Tech stack
go
Domain
devops, security
Issue type
Bug
Difficulty
3/5
Estimated time
1-2 days
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.