Skip to content
This repository was archived by the owner on Jan 7, 2026. It is now read-only.

Conversation

@jamie-albert
Copy link
Member

Summary

Adds pending-upstream-fix advisory for GHSA-r6j8-c6r2-37rr (CVE-2025-13281) in local-static-provisioner package.

Issue

Cherry-picking upstream security commits does not apply cleanly due to code conflicts.

Evidence

Cherry-pick Conflicts

Attempted to cherry-pick commits:

These commits do not apply cleanly to the v2.8.0 tag due to code conflicts.

Source: kubernetes-sigs/sig-storage-local-static-provisioner

Failed Remediation PR

PR #76735 was closed due to cherry-pick conflicts.

Source: wolfi-dev/os PR #76735

Resolution

Upstream kubernetes-sigs/sig-storage-local-static-provisioner maintainers must release a new version (v2.8.1+) containing these security fixes.

References

@jamie-albert jamie-albert requested a review from a team December 23, 2025 20:43
@Ankush-Pathak Ankush-Pathak added this pull request to the merge queue Dec 24, 2025
Merged via the queue into wolfi-dev:main with commit bea4d77 Dec 24, 2025
4 checks passed
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants