Description
<What were you trying to do that didn't work?>
Container score is a B in the advisory. THere are many CVEs listed from all severities.
Steps to reproduce
<What actions did you take to hit the bug?>
1.
2.
3.
Expected result
<What did you expect to happen?>
A score
Actual result
<What actually happened?>
B score
Impact
<How badly does this interfere with using the software?>
We can ship but we would need to fix the higher severity issues soon.
Env
<Where was the bug found, i.e. OCP build, operator build, kata-containers build, cluster infra, test case id>
Additional helpful info
<logs, screenshot, doc links, etc.>
I noticed that the base image used in the dockerfile midstream uses the 9.3 tag
FROM registry.access.redhat.com/ubi9/ubi:9.3
We should at least be using 9.4, but maybe we should be using a golang builder image like we use for many of the other containers.
- links to
-
RHBA-2024:127642 RHBA: sandboxed-containers bug fix and enhancement update
- mentioned on