[ 
https://issues.apache.org/jira/browse/HDDS-14415?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
 ]

Tejaskriya updated HDDS-14415:
------------------------------
    Description: The docker image of ozone has many packages, and mostly older 
versions of packages. For deploying ozone in the kubernetes world, these images 
are critical. It is no longer a "dev-only" usage. the versions of packages like 
goofys and csc needs to be bumped up/ removed.  (was: The docker image of ozone 
has many CVEs. For deploying ozone in the kubernetes world, these images are 
critical. It is no longer a "dev-only" usage. A scan through trivy gave the 
attached report. Most seem to be in goofys and csc. )

> Fixes for ozone's docker image
> ------------------------------
>
>                 Key: HDDS-14415
>                 URL: https://issues.apache.org/jira/browse/HDDS-14415
>             Project: Apache Ozone
>          Issue Type: Bug
>          Components: docker, Security
>            Reporter: Tejaskriya
>            Priority: Major
>
> The docker image of ozone has many packages, and mostly older versions of 
> packages. For deploying ozone in the kubernetes world, these images are 
> critical. It is no longer a "dev-only" usage. the versions of packages like 
> goofys and csc needs to be bumped up/ removed.



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to