Bug report: K3D 5.8.3 release contains Critical and High severity vulnerabilities
Summary
The current K3D 5.8.3 release appears to include dependencies or artefacts that are reported as having Critical and High severity vulnerabilities.
From what I can see, these vulnerabilities may be resolved by rebuilding and re-issuing the release with updated dependencies, even if no other code fixes are included.
Version
Problem
Security scanning of the K3D 5.8.3 release reports Critical and High severity vulnerabilities.
This creates difficulties for users and organisations that rely on vulnerability scanning and security gates, because the current published release is flagged even if the underlying issue could potentially be addressed by refreshing the release artefacts.
Expected behaviour
A refreshed release of K3D 5.8.3, or a new patch release, is published with updated dependencies so that the reported Critical and High severity vulnerabilities are removed where possible.
Actual behaviour
The current K3D 5.8.3 release is flagged by security scanners as containing Critical and High severity vulnerabilities.
Impact
This may prevent adoption or continued use of K3D 5.8.3 in environments where Critical or High severity vulnerabilities block usage, even if the issue can be resolved by rebuilding the release with updated dependencies.
Request
Is there any plan to publish either:
- a refreshed K3D 5.8.3 release with updated dependencies, or
- a new patch release that addresses these vulnerability reports?
Additional context
I appreciate that this may not require functional changes to K3D itself. The main request is to understand whether the maintainers plan to refresh or re-issue the release artefacts to remove the current Critical and High vulnerability findings.
Thanks for your work on K3D.
Bug report: K3D 5.8.3 release contains Critical and High severity vulnerabilities
Summary
The current K3D 5.8.3 release appears to include dependencies or artefacts that are reported as having Critical and High severity vulnerabilities.
From what I can see, these vulnerabilities may be resolved by rebuilding and re-issuing the release with updated dependencies, even if no other code fixes are included.
Version
5.8.3Problem
Security scanning of the K3D 5.8.3 release reports Critical and High severity vulnerabilities.
This creates difficulties for users and organisations that rely on vulnerability scanning and security gates, because the current published release is flagged even if the underlying issue could potentially be addressed by refreshing the release artefacts.
Expected behaviour
A refreshed release of K3D 5.8.3, or a new patch release, is published with updated dependencies so that the reported Critical and High severity vulnerabilities are removed where possible.
Actual behaviour
The current K3D 5.8.3 release is flagged by security scanners as containing Critical and High severity vulnerabilities.
Impact
This may prevent adoption or continued use of K3D 5.8.3 in environments where Critical or High severity vulnerabilities block usage, even if the issue can be resolved by rebuilding the release with updated dependencies.
Request
Is there any plan to publish either:
Additional context
I appreciate that this may not require functional changes to K3D itself. The main request is to understand whether the maintainers plan to refresh or re-issue the release artefacts to remove the current Critical and High vulnerability findings.
Thanks for your work on K3D.