-
Notifications
You must be signed in to change notification settings - Fork 260
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
is there any reason robusta has to stick with python 3.9? #1426
Comments
Hi @tuananh-vpbank, |
And to answer your original question, I don't think there's a fundamental reason to stay w/ 3.9. Just requires testing and verifying that there isn't an issue with any of the dependencies. |
is there a concrete plan to fix / release this I really like using robusta and think it's a bummer that this problem exists at all |
Yes, we plan to fix it in the next few weeks. I've discussed internally and we're prioritizing this. |
Hi @tuananh-vpbank , @Flou21 Today we released version |
many thanks for the update neuvector tells me that high vulnerabilities have gone down from 139 to 63 and medium vulnerabilities from 581 to 83 so not perfect yet, but thanks for the update I really appreciate it |
thanks for the feedback @Flou21 We scanned the image with gcr image scanning, and snyk and it shows only 6 CVEs with severity medium or above. |
Thanks for the information @arikalon1 I use Neuvector to scan all container images in my Kubernetes clusters. I think the biggest problem is the base image rather than robusta itself
And the robusta image 204 with trivy
I still don't understand why the official python image has so many vulnerabilities The newer
More vulnerabilities were also identified in this Snyk WebUI: https://snyk.io/test/docker/python%3A3.11-slim docker hub itself shows less: https://hub.docker.com/layers/library/python/3.11-slim/images/sha256-5a669c7aa9c6d3565ec2d1d50a8344696860ddabb7b8a8f64cfdd38cc932b172?context=explore There are other base images with less / no vulnerabilities.
I think the issue can be closed. |
is there any reason robusta need to stick with python 3.9.
i know that python 3.9 still more than a year left til EOL but the base image has way too many known CVEs. It would be awesome if we can update to a more secure base image.
The text was updated successfully, but these errors were encountered: