-
Notifications
You must be signed in to change notification settings - Fork 2.8k
external-dns v0.20.0 Critical CVEs #6325
Copy link
Copy link
Open
Labels
kind/supportCategorizes issue or PR as a support question.Categorizes issue or PR as a support question.
Description
Our container image scan show there are quite CRITICAL CVEs present in version 0.20.0.
I was able to track a few of them being fixed recently
google.golang.org/grpc bumped to 1.79.3 in this commit https://github.com/kubernetes-sigs/external-dns/commit/e815ee2efe97e488e5c2805db534bfd85d5d61b6
golang.org/x/crypto bumped to 0.45 in commit https://github.com/kubernetes-sigs/external-dns/commit/81162c4b461ab04159b6a1472d5be2fe48c9bc78
I'm unsure if for stdlib CVE-2025-68121is being fixed or not. This doesn't seem to be a direct OR indirect dependency for externa-dns?
Does external-dns have nightly builds that we can use?
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
kind/supportCategorizes issue or PR as a support question.Categorizes issue or PR as a support question.