hpvd opened a new issue, #18338:
URL: https://github.com/apache/pulsar/issues/18338

   ### Search before asking
   
   - [X] I searched in the [issues](https://github.com/apache/pulsar/issues) 
and found nothing similar.
   
   
   ### Version
   
   latest v2.10.2
   
   ### Minimal reproduce step
   
   1. look into trivy powered inspection for vulnerabilities
   at artifacthub.io
   https://artifacthub.io/packages/helm/apache/pulsar?modal=security-report
   
   2. open details of in helm included pulsar v2.10.2 image
   3. see details:
   
   
![2022-11-04_09h25_11](https://user-images.githubusercontent.com/5681880/199929443-5eb31da3-08e4-435c-ad6d-3fed4f015eb6.png)
   
   
![2022-11-04_09h21_54](https://user-images.githubusercontent.com/5681880/199929354-beb78a27-d252-40d0-8b33-1e0083df9d89.png)
   
   
   
   
   ### What did you expect to see?
   
   no fixable vulnerabilities (with severity greater than low) older than some 
month in latest pulsar image.
   At the very least, non older than 1 year
   
   ### What did you see instead?
   
   fixable vulnerabilities of severity CRITICAL with an age of 5 years
   fixable vulnerabilities of severity MEDIUM with an age of 9 years
   
   ### Anything else?
   
   these old security issues are not only a security problem but may also give 
bad impression for the importance of security in our project
   (since we are today already doing great things in this field, this may lead 
to a false impression)
   
   ### Are you willing to submit a PR?
   
   - [ ] I'm willing to submit a PR!


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to