Skip to content
This repository was archived by the owner on Jan 7, 2026. It is now read-only.

Conversation

@mamccorm
Copy link
Member

Related CVE remediation PR: wolfi-dev/os#32618

Unfortunately we are unable to remediate this CVE, and we'll require a fix to be applied upstream. Raising as pending-upstream-fix. See advisory description in this PR for more information.

…ndencies: jetty-http. This relates to GHSA-qh8g-58pp-2wxh, which we are unable to remediate ourselves. Will require a fix upstream.

Signed-off-by: Mark McCormick <mark.mccormick@chainguard.dev>
@mamccorm mamccorm marked this pull request as ready for review November 20, 2024 13:32
Signed-off-by: Mark McCormick <mark.mccormick@chainguard.dev>
@mamccorm mamccorm self-assigned this Nov 20, 2024
@mamccorm mamccorm requested a review from a team November 20, 2024 16:46
mamccorm added a commit to wolfi-dev/os that referenced this pull request Nov 20, 2024
Unfortunately, not all the CVEs [listed in this PR
(initially)](20cc95d),
can be remediated. Removed those which could not, and filed an advisory
for the other:
 - wolfi-dev/advisories#9165

Note, there is a separate `netty-common` finding which is now being
picked up by the scanners but wasn't included in this PR. I am unable to
find the source for this, as there is no netty-common dep defined in any
pom.xml's that I can see. Couldn't easily pin this one down. But not
holding up getting the other fix merged and will address separately.

---------------

neo4j/5.24.2-r0: fix
GHSA-735f-pc8j-v9w8/GHSA-qh8g-58pp-2wxh/GHSA-g8m5-722r-8whq/

Advisory data:
https://github.com/wolfi-dev/advisories/blob/main/neo4j.advisories.yaml

---------

Signed-off-by: Mark McCormick <mark.mccormick@chainguard.dev>
Signed-off-by: Jason Hall <jason@chainguard.dev>
Co-authored-by: octo-sts[bot] <157150467+octo-sts@users.noreply.github.com>
Co-authored-by: Mark McCormick <mark.mccormick@chainguard.dev>
Co-authored-by: Jason Hall <jason@chainguard.dev>
@hbh7 hbh7 added this pull request to the merge queue Nov 20, 2024
Merged via the queue into wolfi-dev:main with commit 3cb6555 Nov 20, 2024
3 checks passed
github-merge-queue bot pushed a commit that referenced this pull request Dec 28, 2024
* Adv(Pending-upstream): advisory has been coppied from #9165

this is a renamed package so all the advisory should be same

Signed-off-by: Debasish Biswas <debasishbsws.dev@gmail.com>

* Yam lint

Signed-off-by: Debasish Biswas <debasishbsws.dev@gmail.com>

---------

Signed-off-by: Debasish Biswas <debasishbsws.dev@gmail.com>
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants