Search before asking
Version
v2.10.2
Minimal reproduce step
look into trivy powered inspection for vulnerabilities
at artifacthub.io
https://artifacthub.io/packages/helm/apache/pulsar?modal=security-report
open details of in the latest helm chart v3.0.0 included pulsar v2.10.2 image
What did you expect to see?
very few fixable vulnerabilities, since v2.10.2 was released just 8 days ago https://github.com/apache/pulsar/releases
What did you see instead?
- 72 vulnerabilities have been detected in the image
- 35 of these should be fixable (most with a version bump of dependencies)


Anything else?
Are you willing to submit a PR?
Search before asking
Version
v2.10.2
Minimal reproduce step
look into trivy powered inspection for vulnerabilities
at artifacthub.io
https://artifacthub.io/packages/helm/apache/pulsar?modal=security-report
open details of in the latest helm chart v3.0.0 included pulsar v2.10.2 image
What did you expect to see?
very few fixable vulnerabilities, since v2.10.2 was released just 8 days ago https://github.com/apache/pulsar/releases
What did you see instead?
Anything else?
[Security] v2.10.2 contains up to 9 year old vulnerabilities/CVEs -> get rid of the oldest #18338
Arguments for "why pulsar is secure?" #18041
[security] further reduction of the 136 vulnerabilities (79 fixable) in helm chart v3.0.0 pulsar-helm-chart#334
Are you willing to submit a PR?