Skip to content

Conversation

@developer-guy
Copy link
Member

Fixes:

Related:

Pre-review Checklist

For new package PRs only

  • This PR is marked as fixing a pre-existing package request bug
    • Alternatively, the PR is marked as related to a pre-existing package request bug, such as a dependency
  • REQUIRED - The package is available under an OSI-approved or FSF-approved license
  • REQUIRED - The version of the package is still receiving security updates
  • REQUIRED - The package is added to packages.txt

For security-related PRs

  • The security fix is recorded in advisories and secfixes

For version bump PRs

  • The epoch field is reset to 0
  • Patch source: patch source here

@developer-guy developer-guy requested a review from a team as a code owner May 29, 2023 20:02
@developer-guy developer-guy requested review from ajayk and rawlingsj May 29, 2023 20:02
@developer-guy developer-guy force-pushed the feature/docker-credential-acr-env branch from e0693bc to 0a4a220 Compare May 29, 2023 20:05
Copy link
Member

@ajayk ajayk left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Address CVE's in the package


golang.org/x/crypto  v0.0.0-20201002170205-7f63de1d35b0  0.0.0-20201216223049-8b5274cf687f  go-module  GHSA-3vm4-22fp-5rfm  High      
golang.org/x/crypto  v0.0.0-20201002170205-7f63de1d35b0  0.0.0-20211202192323-5770296d904e  go-module  GHSA-gwc9-m7rh-j2ww  High      
golang.org/x/crypto  v0.0.0-20201002170205-7f63de1d35b0  0.0.0-20220314234659-1baeb1ce4c0b  go-module  GHSA-8c26-wmh5-6g9v  High      
golang.org/x/sys     v0.0.0-20220325203850-36772127a21f  0.0.0-20220412211240-33da011f77ad  go-module  GHSA-p782-xgp4-8hr8  Medium    
golang.org/x/text    v0.3.3                              0.3.7                              go-module  GHSA-ppp9-7jff-5vj2  High      
golang.org/x/text    v0.3.3                              0.3.8                              go-module  GHSA-69ch-w2m2-3vjp  High

imjasonh
imjasonh previously approved these changes May 29, 2023
@developer-guy developer-guy force-pushed the feature/docker-credential-acr-env branch from 0a4a220 to f070adc Compare May 29, 2023 20:12
@developer-guy developer-guy requested a review from ajayk May 29, 2023 20:12
@developer-guy
Copy link
Member Author

Address CVE's in the package


golang.org/x/crypto  v0.0.0-20201002170205-7f63de1d35b0  0.0.0-20201216223049-8b5274cf687f  go-module  GHSA-3vm4-22fp-5rfm  High      
golang.org/x/crypto  v0.0.0-20201002170205-7f63de1d35b0  0.0.0-20211202192323-5770296d904e  go-module  GHSA-gwc9-m7rh-j2ww  High      
golang.org/x/crypto  v0.0.0-20201002170205-7f63de1d35b0  0.0.0-20220314234659-1baeb1ce4c0b  go-module  GHSA-8c26-wmh5-6g9v  High      
golang.org/x/sys     v0.0.0-20220325203850-36772127a21f  0.0.0-20220412211240-33da011f77ad  go-module  GHSA-p782-xgp4-8hr8  Medium    
golang.org/x/text    v0.3.3                              0.3.7                              go-module  GHSA-ppp9-7jff-5vj2  High      
golang.org/x/text    v0.3.3                              0.3.8                              go-module  GHSA-69ch-w2m2-3vjp  High

fixed @ajayk

@developer-guy developer-guy requested a review from imjasonh May 29, 2023 20:20
ajayk
ajayk previously approved these changes May 29, 2023
@developer-guy developer-guy force-pushed the feature/docker-credential-acr-env branch 3 times, most recently from 017896a to d3e77a7 Compare May 29, 2023 20:47
Signed-off-by: Batuhan Apaydin <batuhan.apaydin@chainguard.dev>
Co-authored-by: Furkan Turkal <furkan.turkal@chainguard.dev>
Signed-off-by: Batuhan Apaydin <batuhan.apaydin@chainguard.dev>
@developer-guy developer-guy force-pushed the feature/docker-credential-acr-env branch from d3e77a7 to 8b4433f Compare May 29, 2023 20:47
@developer-guy developer-guy requested a review from ajayk May 29, 2023 20:51
@ajayk ajayk added this pull request to the merge queue May 29, 2023
Merged via the queue into wolfi-dev:main with commit b9c3571 May 29, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants