-
-
Notifications
You must be signed in to change notification settings - Fork 6
Closed
Description
Remove microdnf and its dependencies if possible to reduce the number of CVEs.
microdnf is not necessary in the operator and product images and can be removed.
For instance, if the following depencies are removed from the Hive 4.0.0 image
microdnf --assumeyes remove \
gnupg2 \
gpgme \
libarchive \
libdnf \
libmodulemd \
librepo \
libsolv \
microdnf \
openldap \
rpm \
rpm-libs
then the following CVEs vanish:
- CVE-2022-3219 (Medium)
- CVE-2023-2953 (High)
- CVE-2023-30571 (Medium)
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
No labels