Skip to content
This repository was archived by the owner on Jan 7, 2026. It is now read-only.

feat(cve remediation): Remediate CVE GHSA-v23v-6jw2-98fq in kaniko#7202

Merged
ritster merged 1 commit into
wolfi-dev:mainfrom
philroche:feature/cve-GHSA-v23v-6jw2-98fq-kaniko
Aug 9, 2024
Merged

feat(cve remediation): Remediate CVE GHSA-v23v-6jw2-98fq in kaniko#7202
ritster merged 1 commit into
wolfi-dev:mainfrom
philroche:feature/cve-GHSA-v23v-6jw2-98fq-kaniko

Conversation

@philroche
Copy link
Copy Markdown
Member

kaniko 1.23.2-r1 is vulnerable to GHSA-v23v-6jw2-98fq/CVE-2024-41110

There has been two attempts at remediating this CVE upstream wit attempted docker
upgrades @ GoogleContainerTools/kaniko#3278 and
GoogleContainerTools/kaniko#3270.

Both attempts failed with failing tests.

As such marking this CVE as pending-upstream-fix.

Links:

GHSA-v23v-6jw2-98fq - GHSA-v23v-6jw2-98fq

Signed-off-by: philroche phil.roche@chainguard.dev

kaniko 1.23.2-r1 is vulnerable to GHSA-v23v-6jw2-98fq/CVE-2024-41110

There has been two attempts at remediating this CVE upstream wit attempted docker
upgrades @ GoogleContainerTools/kaniko#3278 and
GoogleContainerTools/kaniko#3270.

Both attempts failed with failing tests.

As such marking this CVE as pending-upstream-fix.

Links:

GHSA-v23v-6jw2-98fq - GHSA-v23v-6jw2-98fq

Signed-off-by: philroche <phil.roche@chainguard.dev>
@philroche philroche marked this pull request as ready for review August 9, 2024 15:16
@ritster ritster added this pull request to the merge queue Aug 9, 2024
Merged via the queue into wolfi-dev:main with commit f8dca34 Aug 9, 2024
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants