fix-cves

Installation
SKILL.md

Fix CLI CVEs

Fix all vulnerabilities in the Okteto CLI Docker image using systematic vulnerability scanning and remediation.

CONTEXT

  • The source code and Dockerfile for this image are in this repository
  • The Dockerfile includes multiple binaries: kubectl, helm, kustomize, git, syncthing, and the Okteto CLI itself
  • Go dependencies for the Okteto CLI binary are in go.mod and go.sum
  • Go dependencies for internal tools (remote, supervisor, clean) are in tools/go.mod and tools/go.sum
  • Binary versions are defined as ARG variables at the top of the Dockerfile (lines 3-18)
  • Internal tools (remote, supervisor, clean) are built from source in the tools-builder stage
  • Focus on CRITICAL and HIGH severity vulnerabilities first, then address medium/low as needed

WORKFLOW

1. Build and Scan Process

Installs
1
First Seen
Mar 21, 2026
fix-cves from smithery.ai