Skip to content

celeborn-0.5/0.5.4-r1: cve remediation#54633

Merged
bentasker merged 1 commit into
mainfrom
cve-celeborn-0.5-0.5.4-r1-2c89fe5628821664a029718dff47e0d1
May 30, 2025
Merged

celeborn-0.5/0.5.4-r1: cve remediation#54633
bentasker merged 1 commit into
mainfrom
cve-celeborn-0.5-0.5.4-r1-2c89fe5628821664a029718dff47e0d1

Conversation

@octo-sts
Copy link
Copy Markdown
Contributor

@octo-sts octo-sts Bot commented May 29, 2025

celeborn-0.5/0.5.4-r1: fix GHSA-wxr5-93ph-8wr9

Advisory data: https://github.com/wolfi-dev/advisories/blob/main/celeborn-0.5.advisories.yaml


"Breadcrumbs" for this automated service

@octo-sts octo-sts Bot added automated pr celeborn-0.5 GHSA-wxr5-93ph-8wr9 maven/pombump request-cve-remediation bincapz/blocking Bincapz (aka malcontent) scan results detected CRITICALs on the packages. labels May 29, 2025
@bentasker bentasker self-assigned this May 29, 2025
@stevebeattie stevebeattie added the malcontent/reviewed The malcontent findings in this PR have been manually reviewed by security. label May 29, 2025
@stevebeattie
Copy link
Copy Markdown
Member

The false positives around elf headers are due to a bug in malcontent that should be addressed in chainguard-dev/malcontent#969 when it lands.

One other thing to note is that at least some of the elf files that were tripping malcontent up are embedded copies async-profilers (asprof-linux*) which we have packaged in wolfi; I'm not sure how difficult it would be to tell maven to use the system versions while building celeborn.

@bentasker bentasker merged commit b1a13b2 into main May 30, 2025
18 of 19 checks passed
@bentasker bentasker deleted the cve-celeborn-0.5-0.5.4-r1-2c89fe5628821664a029718dff47e0d1 branch May 30, 2025 07:43
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

automated pr bincapz/blocking Bincapz (aka malcontent) scan results detected CRITICALs on the packages. celeborn-0.5 GHSA-wxr5-93ph-8wr9 malcontent/reviewed The malcontent findings in this PR have been manually reviewed by security. maven/pombump request-cve-remediation

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants