rke2-runtime-1.31
Chainguard
Status
Impact
This vulnerability requires non-trivial upstream code changes to replace the affected dependency. RKE2 follows upstream Kubernetes release cycle and implemented these changes in relase v1.33.0+rke2r1, see: https://docs.rke2.io/release-notes/v1.33.X#release-v1330rke2r1 Upstream Kubernetes removed this dependency in the 1.33 release, see: https://github.com/kubernetes/kubernetes/blob/2ac0bdf360cf2529a3675c7012d0bf415e1051f3/CHANGELOG/CHANGELOG-1.33.md?plain=1#L1704 The upstream maintainers of RKE2 would need to backport this fix to the 1.31 branch.
Status