Findings in older 1.13.13 version
Summary
New findings discovered during continuous monitoring. Hi, image version 1.13.13 was patched until last month. Any feedback as whether that image will continue to be maintained? If not, are these findings resolved in the newest versions >= 1.16?
These are 'fixable' as identified by weekly StackRox scans, some dating back to April 24th:
github.com/Azure/azure-sdk-for-go/sdk/azidentity CVE-2024-35255 github.com/go-jose/go-jose/v3 CVE-2024-28180 github.com/go-jose/go-jose/v3 CVE-2025-27144 github.com/golang-jwt/jwt/v4 CVE-2024-51744 github.com/golang-jwt/jwt/v4 CVE-2025-30204 github.com/hashicorp/go-retryablehttp CVE-2024-6104 github.com/hashicorp/go-slug CVE-2025-0377 github.com/jackc/pgproto3/v2 CVE-2024-27304 github.com/jackc/pgx CVE-2024-27304 github.com/jackc/pgx/v4 CVE-2024-27304 github.com/jackc/pgx/v5 CVE-2024-27304 github.com/jackc/pgx/v5 GHSA-fqpg-rq76-99pq github.com/snowflakedb/gosnowflake CVE-2025-46327 go.etcd.io/etcd/client/pkg/v3 GHSA-5x4g-q5rc-36jp golang.org/x/crypto CVE-2024-45337 golang.org/x/crypto CVE-2025-22869 golang.org/x/net CVE-2023-45288 golang.org/x/net CVE-2025-22870 golang.org/x/net CVE-2025-22872 google.golang.org/protobuf CVE-2024-24786
Tasks
Contributor:
-
Provide justifications for findings in the VAT (docs) -
Apply the StatusVerification label to this issue and wait for feedback
Note: You must mannually apply the StatusVerification label, in order to have a CHT member review your merge request.
Iron Bank:
-
Review findings and justifications -
Close issue
Note: If the above process is rejected for any reason, the
Status::Verificationlabel will be removed and the issue will be sent back toOpen. Any comments will be listed in this issue for you to address. Once they have been addressed, you must re-add theStatus::Verificationlabel.
Questions?
Contact the Iron Bank team by commenting on this issue with your questions or concerns. If you do not receive a response, add /cc @ironbank-notifications/onboarding.
Additionally, Iron Bank hosts an AMA working session every Wednesday from 1630-1730EST to answer questions.