Skip to content

K3D 5.8.3 release contains Critical and High severity vulnerabilities #1669

Description

@lmerlas

Bug report: K3D 5.8.3 release contains Critical and High severity vulnerabilities

Summary

The current K3D 5.8.3 release appears to include dependencies or artefacts that are reported as having Critical and High severity vulnerabilities.

From what I can see, these vulnerabilities may be resolved by rebuilding and re-issuing the release with updated dependencies, even if no other code fixes are included.

Version

  • K3D version: 5.8.3

Problem

Security scanning of the K3D 5.8.3 release reports Critical and High severity vulnerabilities.

This creates difficulties for users and organisations that rely on vulnerability scanning and security gates, because the current published release is flagged even if the underlying issue could potentially be addressed by refreshing the release artefacts.

Expected behaviour

A refreshed release of K3D 5.8.3, or a new patch release, is published with updated dependencies so that the reported Critical and High severity vulnerabilities are removed where possible.

Actual behaviour

The current K3D 5.8.3 release is flagged by security scanners as containing Critical and High severity vulnerabilities.

Impact

This may prevent adoption or continued use of K3D 5.8.3 in environments where Critical or High severity vulnerabilities block usage, even if the issue can be resolved by rebuilding the release with updated dependencies.

Request

Is there any plan to publish either:

  • a refreshed K3D 5.8.3 release with updated dependencies, or
  • a new patch release that addresses these vulnerability reports?

Additional context

I appreciate that this may not require functional changes to K3D itself. The main request is to understand whether the maintainers plan to refresh or re-issue the release artefacts to remove the current Critical and High vulnerability findings.

Thanks for your work on K3D.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't working

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions