diff --git a/kaniko.advisories.yaml b/kaniko.advisories.yaml index 78aad1675..005760e8e 100644 --- a/kaniko.advisories.yaml +++ b/kaniko.advisories.yaml @@ -97,6 +97,10 @@ advisories: componentType: go-module componentLocation: /usr/bin/executor scanner: grype + - timestamp: 2024-08-09T15:11:43Z + type: pending-upstream-fix + data: + note: There has been two attempts at remediating this CVE upstream wit attempted docker upgrades @ https://github.com/GoogleContainerTools/kaniko/pull/3278 and https://github.com/GoogleContainerTools/kaniko/pull/3270. Both attempts failed with failing tests. As such marking this CVE as pending-upstream-fix. - id: CGA-f5hh-5rrg-27h8 aliases: