hpvd commented on issue #294:
URL: 
https://github.com/apache/pulsar-helm-chart/issues/294#issuecomment-1303176871

   wow just saw the latest release 3.0.0!
   What a great progress :-)
   
   just did the same quick security check up again:
   
   Latest security analysis show
   - a stunning step in reducing the number of included vulnerabilities (minus 
85%!)
     - v2.9.4 with pulsar 2.9.3 **1024 vulnerabilities (698 fixable) have been 
detected in this package's images.**
   
https://artifacthub.io/packages/helm/apache/pulsar/2.9.4?modal=security-report
     - v3.0.0 with pulsar 2.10.2 **136 vulnerabilities (79 fixable) have been 
detected in this package's images.**
   https://artifacthub.io/packages/helm/apache/pulsar?modal=security-report
   - on the other hand
     - the number of fixable vulnerabilities with a severity of CRITICAL has 
risen from 1 to 4 (plus 300%!)
    
   
![2022-11-04_10h05_52](https://user-images.githubusercontent.com/5681880/199936712-593036aa-b445-4c6a-990a-4951e5487c28.png)
   
   
![2022-11-04_10h07_06](https://user-images.githubusercontent.com/5681880/199936741-a8f2139b-f055-4f2a-b74d-fbdaa59bf909.png)
   
     - very old fixable and already reported vulnerabilities (up to 9 years 
old) are still included:
      
   
![2022-11-04_09h21_54](https://user-images.githubusercontent.com/5681880/199937604-17826ab6-0d4d-469d-a1cd-7df6019138bb.png)
   
   edit: just opened a separate issue for this: 
https://github.com/apache/pulsar/issues/18338


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to