helm / chartmuseum

helm chart repository server

Home Page:https://chartmuseum.com

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

Found security vulnerability in chartmuseum v0.15.0

Kiran-38 opened this issue · comments

Hi,
The chartMuseum binary contains the go.etcd.io/etcd-v3.3.27+incompatible, github.com/containerd/containerd-v1.6.1 library with is flagged as a security risk and need to update to the latest version available for resolving the issue.

The mentioned library is coming as a derived dependency, as is verified by searching for it in the go.mod file. It is because of this vulnerable library that all the images having even the latest chartMuseum binary baked into them are failing the security scans.