This topic lists the security fixes in Tanzu Application Platform v1.8 releases.
In this topic:
This release has the following security fixes, listed by component and area.
This release has the following security fixes, listed by package.
This release has the following security fixes, listed by package.
This release has the following security fixes, listed by package.
This release has the following security fixes, listed by package.
This release has the following security fixes, listed by package.
This release has the following security fixes, listed by package.
Package Name | Vulnerabilities Resolved |
---|---|
alm-catalog.component.apps.tanzu.vmware.com |
Expand to see the list |
app-scanning.apps.tanzu.vmware.com |
Expand to see the list |
base-jammy-stack-lite.buildpacks.tanzu.vmware.com |
Expand to see the list
|
carbonblack.scanning.apps.tanzu.vmware.com |
Expand to see the list |
conventions.component.apps.tanzu.vmware.com | |
git-writer.component.apps.tanzu.vmware.com | |
grype.scanning.apps.tanzu.vmware.com |
Expand to see the list |
metadata-store.apps.tanzu.vmware.com | |
ruby-lite.buildpacks.tanzu.vmware.com |
Expand to see the list |
scanning.apps.tanzu.vmware.com |
Expand to see the list |
snyk.scanning.apps.tanzu.vmware.com |
Expand to see the list |
source.component.apps.tanzu.vmware.com |
Expand to see the list |
spring-cloud-gateway.tanzu.vmware.com |
Expand to see the list
|
sso.apps.tanzu.vmware.com | |
supply-chain-catalog.apps.tanzu.vmware.com | |
tap-gui.tanzu.vmware.com |
Expand to see the list |
trivy.app-scanning.component.apps.tanzu.vmware.com |
Expand to see the list |
This release has the following security fixes, listed by package.
Package Name | Vulnerabilities Resolved |
---|---|
accelerator.apps.tanzu.vmware.com | |
amr-observer.apps.tanzu.vmware.com |
Expand to see the list |
api-portal.tanzu.vmware.com |
Expand to see the list |
apiserver.appliveview.tanzu.vmware.com |
Expand to see the list |
app-scanning.apps.tanzu.vmware.com | |
aws.services.tanzu.vmware.com |
Expand to see the list
|
backend.appliveview.tanzu.vmware.com |
Expand to see the list |
buildservice.tanzu.vmware.com | |
carbonblack.scanning.apps.tanzu.vmware.com |
Expand to see the list |
cnrs.tanzu.vmware.com |
Expand to see the list |
connector.appliveview.tanzu.vmware.com |
Expand to see the list |
conventions.appliveview.tanzu.vmware.com |
Expand to see the list |
crossplane.tanzu.vmware.com | |
developer-conventions.tanzu.vmware.com |
Expand to see the list |
dotnet-core-lite.buildpacks.tanzu.vmware.com |
Expand to see the list |
grype.scanning.apps.tanzu.vmware.com |
Expand to see the list |
java-lite.buildpacks.tanzu.vmware.com |
Expand to see the list |
java-native-image-lite.buildpacks.tanzu.vmware.com |
Expand to see the list |
metadata-store.apps.tanzu.vmware.com | |
namespace-provisioner.apps.tanzu.vmware.com | |
nodejs-lite.buildpacks.tanzu.vmware.com | |
ootb-supply-chain-testing-scanning.tanzu.vmware.com | |
ootb-templates.tanzu.vmware.com | |
python-lite.buildpacks.tanzu.vmware.com |
Expand to see the list |
scanning.apps.tanzu.vmware.com |
Expand to see the list |
servicebinding.tanzu.vmware.com |
Expand to see the list |
services-toolkit.tanzu.vmware.com |
Expand to see the list |
snyk.scanning.apps.tanzu.vmware.com |
Expand to see the list |
sso.apps.tanzu.vmware.com | |
tap-gui.tanzu.vmware.com |
Expand to see the list
|
Kernel level vulnerabilities are regularly identified and patched by Canonical. Tanzu Application Platform releases with available images, which might contain known vulnerabilities. When Canonical makes patched images available, Tanzu Application Platform incorporates these fixed images into future releases.
The kernel runs on your container host VM, not the Tanzu Application Platform container image. Even with a patched Tanzu Application Platform image, the vulnerability is not mitigated until you deploy your containers on a host with a patched OS. An unpatched host OS might be exploitable if the base image is deployed.