Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Dependabot Vulnerabilities identified in scan of v1.10.2 #7140

Closed
shikari7 opened this issue May 8, 2024 · 4 comments
Closed

Dependabot Vulnerabilities identified in scan of v1.10.2 #7140

shikari7 opened this issue May 8, 2024 · 4 comments
Labels
kind/bug 🐞 Something isn't working

Comments

@shikari7
Copy link

shikari7 commented May 8, 2024

Bug description

Dependabot is reporting the attached vulnerabilities in Podman Desktop 1.10.2.

Operating system

all

Installation Method

Other

Version

1.10.2

Steps to reproduce

Dependabot scans of install tool - see attachment for output

Relevant log output

No response

Additional context

No response

@shikari7 shikari7 added the kind/bug 🐞 Something isn't working label May 8, 2024
@shikari7
Copy link
Author

shikari7 commented May 8, 2024

@benoitf
Copy link
Collaborator

benoitf commented May 13, 2024

dependabot report is part of https://github.com/containers/podman-desktop/security no need to have dedicated issues for that

@benoitf benoitf closed this as not planned Won't fix, can't repro, duplicate, stale May 13, 2024
@shikari7
Copy link
Author

Hey @benoitf thanks for that info - these findings from Dependabot have been present in the last several released versions of Podman Desktop - what is the process for remediating these as part of the release process?

These findings are impeding use of Podman Desktop in highly secure environments.

@shikari7
Copy link
Author

hi @benoitf sorry to bother you, can you help me understand how to help get these Dependabot findings remediated? Thank you.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
kind/bug 🐞 Something isn't working
Projects
Archived in project
Development

No branches or pull requests

3 participants