This repository was archived by the owner on Jan 7, 2026. It is now read-only.
local-static-provisioner: add pending-upstream-fix advisory for GHSA-r6j8-c6r2-37rr #28161
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Summary
Adds
pending-upstream-fixadvisory for GHSA-r6j8-c6r2-37rr (CVE-2025-13281) in local-static-provisioner package.Issue
Cherry-picking upstream security commits does not apply cleanly due to code conflicts.
Evidence
Cherry-pick Conflicts
Attempted to cherry-pick commits:
2edb740e03b22a619e832176ba0d4c30ba1f9f92: fix CVE-2025-5187fbbab741296e295136f60d1de5996ad7a9e90d02: fix CVE-2025-13281These commits do not apply cleanly to the v2.8.0 tag due to code conflicts.
Source: kubernetes-sigs/sig-storage-local-static-provisioner
Failed Remediation PR
PR #76735 was closed due to cherry-pick conflicts.
Source: wolfi-dev/os PR #76735
Resolution
Upstream kubernetes-sigs/sig-storage-local-static-provisioner maintainers must release a new version (v2.8.1+) containing these security fixes.
References