Skip to content

Commit

Permalink
Merge pull request wolfi-dev#1187 from hectorj2f/skaffold_adv
Browse files Browse the repository at this point in the history
skaffold: pending-upstream-fix
  • Loading branch information
pdeslaur authored Feb 11, 2024
2 parents c07c57c + 8f6d811 commit e24e069
Showing 1 changed file with 8 additions and 0 deletions.
8 changes: 8 additions & 0 deletions skaffold.advisories.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -101,6 +101,10 @@ advisories:
componentType: go-module
componentLocation: /usr/bin/skaffold
scanner: grype
- timestamp: 2024-02-11T12:48:47Z
type: pending-upstream-fix
data:
note: Upgrading runc to a non-vulnerable version creates conflicts with other old dependencies required by skaffold such as go.opentelemetry.io/otel which is using v1.15.0.

- id: CVE-2024-23650
aliases:
Expand Down Expand Up @@ -169,6 +173,10 @@ advisories:
componentType: go-module
componentLocation: /usr/bin/skaffold
scanner: grype
- timestamp: 2024-02-11T12:50:32Z
type: pending-upstream-fix
data:
note: Upgrading buildkit to a non-vulnerable version requires to bump github.com/docker/docker to v25.0.3 (currently using v24.0.7) and as a consequence needs multiple code changes to adapt the source code to this new version.

- id: GHSA-7ww5-4wqc-m92c
events:
Expand Down

0 comments on commit e24e069

Please sign in to comment.