Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

management-api-for-apache-cassandra/0.1.78 package update #19655

Closed
wants to merge 2 commits into from

Conversation

octo-sts[bot]
Copy link
Contributor

@octo-sts octo-sts bot commented May 17, 2024

Signed-off-by: wolfi-bot <121097084+wolfi-bot@users.noreply.github.com>
@rawlingsj rawlingsj marked this pull request as draft May 17, 2024 08:22
@rawlingsj
Copy link
Member

Think we still need the patch to fix CVEs, there's some extra ones showing up too. Gonna switch it to pom bump to see if that helps.

@mamccorm
Copy link
Contributor

Fixed as part of:
#19982

There remains one CVE:

"/tmp/artifacts-1/packages/x86_64/management-api-for-apache-cassandra-0.1.78-r0.apk"
└── 📄 /opt/management-api/datastax-mgmtapi-agent-5.0.x-0.1.0-SNAPSHOT.jar
        📦 netty-codec-http 4.1.96.Final (java-archive)
            Medium CVE-2024-29025 GHSA-5jpm-x58v-624v fixed in 4.1.108.Final

We'll either need an advisory, or delete the files in question - as upstream seems to simply delete those files?

@mamccorm mamccorm closed this May 23, 2024
@octo-sts octo-sts bot deleted the wolfictl-aab042bd-200c-4d4d-aec8-117723f64f77 branch May 30, 2024 16:57
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
automated pr request-version-update request for a newer version of a package
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

4 participants