Skip to content

Investigate unresolved MySQL helper-component CVEs in mysql:8.4 #435

@josecelano

Description

@josecelano

Overview

Track unresolved MySQL image vulnerabilities after remediation pass 1 in issue #428.

Context

Current scan for mysql:8.4 reports:

  • 7 HIGH
  • 1 CRITICAL

Findings are primarily in helper components (gosu and Python packages), not MySQL server core.

Goals

  • Validate if any compatible MySQL image variant/tag reduces the gosu/Python findings
  • Determine mitigation options while preserving LTS/stability requirements
  • Document risk acceptance path if no practical low-risk upgrade exists

Acceptance Criteria

  • Compare compatible MySQL tags/variants with vulnerability deltas
  • Document recommended strategy (upgrade, pin, or monitored acceptance)
  • Update deployer defaults if an improved option is validated
  • Pre-commit checks pass: ./scripts/pre-commit.sh

Related

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions