Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Request to Update hubble-ui Image Due to Outdated NGINX Version (EOL) #942

Open
kennethsinyeung opened this issue Jan 17, 2025 · 1 comment
Assignees
Labels
dependencies Pull requests that update a dependency file
Milestone

Comments

@kennethsinyeung
Copy link

Dear Cilium Team, there is a vulnerability finding for the latest hubble-ui image https://hubgw.docker.com/layers/cilium/hubble-ui/v0.13.1/images/sha256-306c8accedc8eb0dd31b128ce71767d8ff16d7623605e2559217ac563b8e17da . The image layer contains nginx v1.25.5 which has reached its End of Life. To ensure ongoing security and compatibility, could you please update the image with a newer version of NGINX (at least v1.26.2)?

@yannikmesserli
Copy link
Contributor

We will release a new security patch for Hubble UI on Feb 18th. Sorry for the delay, we have gone through big internal projects and have left Hubble UI's health unintended.

@yannikmesserli yannikmesserli added this to the v0.13.2 milestone Jan 17, 2025
@yannikmesserli yannikmesserli added the dependencies Pull requests that update a dependency file label Jan 17, 2025
@yannikmesserli yannikmesserli self-assigned this Jan 17, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
dependencies Pull requests that update a dependency file
Projects
None yet
Development

No branches or pull requests

2 participants