-
Bug
-
Resolution: Unresolved
-
Major
-
None
-
None
-
False
-
-
False
-
-
When installing the Web Terminal operator in OCP 4.17, last version available in the cluster is 1.12.1 (using the image registry.redhat.io/web-terminal/web-terminal-rhel9-operator@sha256:c076316fda155cd1583b12dac605e10c8a90347332f1328b6078685df3fc2f0b).
Checking that image in the Red Hat Catalog, it's [1] (as per the the sha256). In the catalog, that image tag is 1.12-6 (while it's only a tag, it's confusing the version of the operator and the tag of the image are different).
That image is 4 months old, and it have some vulnerabilities (that can be checked in the "Security" tab in [1]). For the same image, there are new versions releases 21 days ago as can be shown in the dropdown (with tags like 1.12-6.17xxxx, and one with also tag 1.12) with not vulnerabilities.
Currently, it is not possible to use one of the latest images images for installing/updating the web-terminal operator.
Is there a way to upgrade the operator to use the latest image version, which have the vulnerabilities already fixed? Why is not last version of the image already available in the OperatorHub in the cluster?