Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
What are we trying to fix?
Found some high risk CVEs on our clusters. Listed the CVEs in attached json file.
cves.json
Upgrading the patch version of EKS and containerd packages used in this driver.
How can we find the CVEs?
We use ORCA scanner for detecting vulnerabilities. Run the ORCA scan on CSI driver image built in this repository.
Some other details
Kubernetes version
v1.26
Cloud Provider
EKS
Container runtime (CRI) and version
Containerd v1.7.2
CSI driver image and version
docker.io/warmmetal/csi-image v1.2.0