Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Bump kiali dependency to the latest possible version #137

Open
azuterios opened this issue May 26, 2023 · 3 comments
Open

Bump kiali dependency to the latest possible version #137

azuterios opened this issue May 26, 2023 · 3 comments

Comments

@azuterios
Copy link

Dear Tetratelabs Team,

Please up the kiali version in the go code. There is an existing dependency for version 1.43+, but it's being replaced with an older package here:

getmesh/go.mod

Line 101 in 6089ff1

replace github.com/kiali/kiali => github.com/kiali/kiali v1.29.1-0.20210125202741-72d2ce2fceb5

Currently, getmesh version 1.1.5 vulnerability scan comes up with a CVE vulnerability, which is older than 1 year - CVE-2021-20278
https://nvd.nist.gov/vuln/detail/CVE-2021-20278

Please remove the replacement or replace it with a newer version and release it. Thank you!

azuterios

@Bjyothi2023
Copy link

One other vulnerability "CVE-2021-3495" is reported by vulnerability scanner.
Reason : github.com/kiali/kiali
version : v1.29.1-0.20210125202741-72d2ce2fceb5
Fix is available in version : 1.33.0

Kindly update the "github.com/kiali/kiali" version to 1.33.0 to fix this vulnerability

@Bjyothi2023
Copy link

Hello Team, Could you please help resolving this issue. It is impacting the projects that are using this tool , as the Vulnerability scanner are reporting these issues and it is blocking us from proceeding further.

@azuterios
Copy link
Author

Dear Tetratelabs Team,

This issue has been stale for some time now, could you be able to provide us with an estimate, when the change might happen and if it's possible to happen at all?

Thank you for the support on this!

azuterios

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants