Skip to content

Conversation

@jupyterhub-bot
Copy link
Collaborator

A rebuild of quay.io/jupyterhub/k8s-hub has been found to influence the detected vulnerabilities! This PR will trigger a rebuild because it has updated a comment in the Dockerfile.

About

This scan for known vulnerabilities has been made by aquasecurity/trivy. Trivy was configured to filter the vulnerabilities with the following settings:

  • ignore-unfixed: true

Before

Before trying to rebuild the image, the following vulnerabilities was detected in quay.io/jupyterhub/k8s-hub:4.2.1-0.dev.git.7084.h2c1c71d9.

Target Vuln. ID Package Name Installed v. Fixed v.
debian CVE-2022-49043 libxml2 2.9.14+dfsg-1.3~deb12u1 2.9.14+dfsg-1.3~deb12u2
debian CVE-2023-39615 libxml2 2.9.14+dfsg-1.3~deb12u1 2.9.14+dfsg-1.3~deb12u2
debian CVE-2023-45322 libxml2 2.9.14+dfsg-1.3~deb12u1 2.9.14+dfsg-1.3~deb12u2
debian CVE-2024-25062 libxml2 2.9.14+dfsg-1.3~deb12u1 2.9.14+dfsg-1.3~deb12u2
debian CVE-2024-34459 libxml2 2.9.14+dfsg-1.3~deb12u1 2.9.14+dfsg-1.3~deb12u2
debian CVE-2024-56171 libxml2 2.9.14+dfsg-1.3~deb12u1 2.9.14+dfsg-1.3~deb12u2
debian CVE-2025-24928 libxml2 2.9.14+dfsg-1.3~deb12u1 2.9.14+dfsg-1.3~deb12u2
debian CVE-2025-27113 libxml2 2.9.14+dfsg-1.3~deb12u1 2.9.14+dfsg-1.3~deb12u2
debian CVE-2025-32414 libxml2 2.9.14+dfsg-1.3~deb12u1 2.9.14+dfsg-1.3~deb12u2
debian CVE-2025-32415 libxml2 2.9.14+dfsg-1.3~deb12u1 2.9.14+dfsg-1.3~deb12u2
debian CVE-2025-5222 libicu72 72.1-3 72.1-3+deb12u1

After

Target Vuln. ID Package Name Installed v. Fixed v.

@jupyterhub-bot jupyterhub-bot added the image:rebuild-to-patch-vuln Image rebuild to patch a known external vulnerability label Jun 30, 2025
@consideRatio consideRatio merged commit 0916158 into main Jul 8, 2025
16 checks passed
@consideRatio consideRatio deleted the vuln-scan-hub branch July 8, 2025 12:53
consideRatio pushed a commit to jupyterhub/helm-chart that referenced this pull request Jul 8, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

image:rebuild-to-patch-vuln Image rebuild to patch a known external vulnerability

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants