incalculable-air-54033
04/12/2023, 2:01 PMbig-judge-33880
04/12/2023, 2:07 PMincalculable-air-54033
04/12/2023, 2:26 PMrancher/hardened-build-base:v1.20.3b1
and only installing the necessary packages.
I saw mention of Trivy too, but infact Trivy detects quite a few issues against this particular imagecreamy-pencil-82913
04/12/2023, 3:37 PMI can’t see to find anything to explain what has gone into that process.https://docs.rke2.io/security/about_hardened_images
incalculable-air-54033
04/12/2023, 3:51 PMRKE2 hardened images are scanned for vulnerabilities at build time
Any idea on what warrants a 'fix' based on the output of these scans? Only vulnerable components which can actively be exploited are fixed? Or any vulnerable component, regardless of exploitability?creamy-pencil-82913
04/12/2023, 4:02 PMincalculable-air-54033
04/13/2023, 7:40 AMrancher/hardened-etcd:v3.5.7-k3s1-build20230406
, (Albeit with Snyk, so a different detection engine) and noticed there are still issues against the golang libraries. Should i be reporting these? Or is it that you guys only fix issues if there are active exploits against them?creamy-pencil-82913
04/13/2023, 5:01 PMincalculable-air-54033
04/13/2023, 5:28 PMcreamy-pencil-82913
04/13/2023, 6:25 PMincalculable-air-54033
04/14/2023, 7:35 AM