Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
fix: Upgrade packages to latest version (#75)
By checking the code there were some security vulnerabities present in the net-tools binary such has: usr/local/bin/nats-top (gobinary) Total: 3 (UNKNOWN: 1, LOW: 0, MEDIUM: 1, HIGH: 1, CRITICAL: 0) ┌─────────────────────┬─────────────────────┬──────────┬────────────────────────────────────┬───────────────────────────────────┬────────────────────────────────────────────────────────────┐ │ Library │ Vulnerability │ Severity │ Installed Version │ Fixed Version │ Title │ ├─────────────────────┼─────────────────────┼──────────┼────────────────────────────────────┼───────────────────────────────────┼────────────────────────────────────────────────────────────┤ │ golang.org/x/crypto │ CVE-2022-27191 │ HIGH │ v0.0.0-20220112180741-5e0467b6c7ce │ 0.0.0-20220314234659-1baeb1ce4c0b │ golang: crash in a golang.org/x/crypto/ssh server │ │ │ │ │ │ │ https://avd.aquasec.com/nvd/cve-2022-27191 │ │ ├─────────────────────┼──────────┤ │ ├────────────────────────────────────────────────────────────┤ │ │ GHSA-8c26-wmh5-6g9v │ UNKNOWN │ │ │ Attackers can cause a crash in SSH servers when the server │ │ │ │ │ │ │ has... │ │ │ │ │ │ │ GHSA-8c26-wmh5-6g9v │ ├─────────────────────┼─────────────────────┼──────────┼────────────────────────────────────┼───────────────────────────────────┼────────────────────────────────────────────────────────────┤ │ golang.org/x/sys │ CVE-2022-29526 │ MEDIUM │ v0.0.0-20220111092808-5a964db01320 │ 0.0.0-20220412211240-33da011f77ad │ golang: syscall: faccessat checks wrong group │ │ │ │ │ │ │ https://avd.aquasec.com/nvd/cve-2022-29526 │ └─────────────────────┴─────────────────────┴──────────┴────────────────────────────────────┴───────────────────────────────────┴────────────────────────────────────────────────────────────┘ These results come from Trivy from the nats-box image. Upgrading the packages fixed inner dependencies and these crypto and sys packages were upgraded to the latest version.
- Loading branch information