fix-cves
Installation
SKILL.md
Fix CLI CVEs
Fix all vulnerabilities in the Okteto CLI Docker image using systematic vulnerability scanning and remediation.
CONTEXT
- The source code and Dockerfile for this image are in this repository
- The Dockerfile includes multiple binaries: kubectl, helm, kustomize, git, syncthing, and the Okteto CLI itself
- Go dependencies for the Okteto CLI binary are in
go.modandgo.sum - Go dependencies for internal tools (remote, supervisor, clean) are in
tools/go.modandtools/go.sum - Binary versions are defined as ARG variables at the top of the Dockerfile (lines 3-18)
- Internal tools (remote, supervisor, clean) are built from source in the
tools-builderstage - Focus on CRITICAL and HIGH severity vulnerabilities first, then address medium/low as needed