Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

chromium/126.0.6478.182 package update #24107

Merged
merged 2 commits into from
Jul 17, 2024

Conversation

octo-sts[bot]
Copy link
Contributor

@octo-sts octo-sts bot commented Jul 17, 2024

@octo-sts octo-sts bot added request-version-update request for a newer version of a package automated pr P1 This label indicates our scanning found High, Medium or Low CVEs for these packages. labels Jul 17, 2024
Copy link
Contributor Author

octo-sts bot commented Jul 17, 2024

Open AI suggestions to solve the build error:

The error message is: "fatal: detected dubious ownership in repository at '/github/home'
To add an exception for this directory, call:

git config --global --add safe.directory /github/home"

To fix this error, follow these steps:
1. Open your terminal.
2. Run: `git config --global --add safe.directory /github/home`
3. Verify by running: `git config --global --get-all safe.directory`

@ajayk ajayk enabled auto-merge July 17, 2024 05:10
Copy link
Contributor

Package chromium-docker-selenium-compat: Click to expand/collapse

Package chromium-docker-selenium-compat:
Modified: /opt/selenium/browser_version

Package chromium: Click to expand/collapse

Package chromium:
Modified: /usr/lib/chromium/chrome
Modified: /usr/lib/chromium/chrome_100_percent.pak
Modified: /usr/lib/chromium/chrome_200_percent.pak
Modified: /usr/lib/chromium/chrome_crashpad_handler
Modified: /usr/lib/chromium/chrome_sandbox
Modified: /usr/lib/chromium/chromedriver
Modified: /usr/lib/chromium/headless_lib_data.pak
Modified: /usr/lib/chromium/libEGL.so
Modified: /usr/lib/chromium/libGLESv2.so
Modified: /usr/lib/chromium/libVkICD_mock_icd.so
Modified: /usr/lib/chromium/libVkLayer_khronos_validation.so
Modified: /usr/lib/chromium/libvk_swiftshader.so
Modified: /usr/lib/chromium/libvulkan.so.1
Modified: /usr/lib/chromium/locales
Modified: /usr/lib/chromium/resources.pak
Modified: /usr/lib/chromium/snapshot_blob.bin
Modified: /usr/lib/chromium/v8_context_snapshot.bin

Package chromium-qt: Click to expand/collapse

Package chromium-qt:
Modified: /usr/lib/chromium/libqt5_shim.so

Package chromium-lang: Click to expand/collapse

Package chromium-lang:
Modified: /usr/lib/chromium/locales/am.pak
Modified: /usr/lib/chromium/locales/bn.pak
Modified: /usr/lib/chromium/locales/ca.pak
Modified: /usr/lib/chromium/locales/cs.pak
Modified: /usr/lib/chromium/locales/de.pak
Modified: /usr/lib/chromium/locales/el.pak
Modified: /usr/lib/chromium/locales/en-GB.pak
Modified: /usr/lib/chromium/locales/es-419.pak
Modified: /usr/lib/chromium/locales/es.pak
Modified: /usr/lib/chromium/locales/fa.pak
Modified: /usr/lib/chromium/locales/fr.pak
Modified: /usr/lib/chromium/locales/he.pak
Modified: /usr/lib/chromium/locales/hi.pak
Modified: /usr/lib/chromium/locales/hr.pak
Modified: /usr/lib/chromium/locales/id.pak
Modified: /usr/lib/chromium/locales/it.pak
Modified: /usr/lib/chromium/locales/ja.pak
Modified: /usr/lib/chromium/locales/kn.pak
Modified: /usr/lib/chromium/locales/ko.pak
Modified: /usr/lib/chromium/locales/ms.pak
Modified: /usr/lib/chromium/locales/nb.pak
Modified: /usr/lib/chromium/locales/pl.pak
Modified: /usr/lib/chromium/locales/pt-BR.pak
Modified: /usr/lib/chromium/locales/ro.pak
Modified: /usr/lib/chromium/locales/ru.pak
Modified: /usr/lib/chromium/locales/sr.pak
Modified: /usr/lib/chromium/locales/sv.pak
Modified: /usr/lib/chromium/locales/tr.pak
Modified: /usr/lib/chromium/locales/uk.pak
Modified: /usr/lib/chromium/locales/vi.pak
Modified: /usr/lib/chromium/locales/zh-CN.pak

bincapz found differences: Click to expand/collapse

Changed: /tmp/wolfictl-apk-4262595402/chromium/usr/lib/chromium/chrome

Moved: chromium-qt/var/lib/db/sbom/chromium-qt-126.0.6478.126-r0.spdx.json -> /tmp/wolfictl-apk-4262595402/chromium-lang/var/lib/db/sbom/chromium-lang-126.0.6478.182-r0.spdx.json (similarity: 0.92)

Changed: /tmp/wolfictl-apk-4262595402/chromium/var/lib/db/sbom/chromium-126.0.6478.182-r0.spdx.json

Moved: chromium-lang/var/lib/db/sbom/chromium-lang-126.0.6478.126-r0.spdx.json -> /tmp/wolfictl-apk-4262595402/chromium-qt/var/lib/db/sbom/chromium-qt-126.0.6478.182-r0.spdx.json (similarity: 0.92)

Changed: /tmp/wolfictl-apk-4262595402/chromium-docker-selenium-compat/var/lib/db/sbom/chromium-docker-selenium-compat-126.0.6478.182-r0.spdx.json

Copy link
Contributor Author

octo-sts bot commented Jul 17, 2024

bincapz detected files with a risk score equal or higher than 'CRITICAL': Click to expand/collapse

/tmp/bincapz2507943857/packages/x86_64/chromium-126.0.6478.182-r0.apk/usr/lib/chromium/chrome [🚨 CRITICAL]

RISK KEY DESCRIPTION EVIDENCE
CRITICAL combo/stealer/browser Makes references to multiple browser credentials .config
Cookies
Firefox
Google Chrome
User Data
formhistory.sqlite
places.sqlite

@egibs
Copy link
Member

egibs commented Jul 17, 2024

@hectorj2f -- looks like the build failed due to the file system running out of space:

2024/07/17 04:15:10 ERRO failed to clone https://chromium.googlesource.com/chromium/src.git ref 126.0.6478.182: write /tmp/wolfictl1653378409/.git/objects/pack/tmp_pack_2829125991: no space left on device

Once that's fixed I can grab the artifact for inspection.

Edit:

I grabbed the file in question from the latest Chromium image.

@ajayk ajayk merged commit a19fd4e into main Jul 17, 2024
7 of 8 checks passed
@ajayk ajayk deleted the wolfictl-9f0e9469-4d48-4aa4-955a-4552a6734e1c branch July 17, 2024 18:56
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
automated pr P1 This label indicates our scanning found High, Medium or Low CVEs for these packages. request-version-update request for a newer version of a package service:bincapz/blocking
Projects
None yet
Development

Successfully merging this pull request may close these issues.

4 participants