Skip to content

Update infrabits/ci-pack digest to e6fda6b - #43

Merged
renovate[bot] merged 1 commit into
mainfrom
renovate/infrabits-ci-pack-digest
Jun 2, 2026
Merged

Update infrabits/ci-pack digest to e6fda6b#43
renovate[bot] merged 1 commit into
mainfrom
renovate/infrabits-ci-pack-digest

Conversation

@renovate

@renovate renovate Bot commented Jun 1, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Type Update Change
infrabits/ci-pack (changelog) action digest 001c648e6fda6b

Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@github-actions

github-actions Bot commented Jun 1, 2026

Copy link
Copy Markdown

Trivy Security Scan

ghcr.io/cluebotng/fileserver:c9d5f53ce7dad99df9bd68353218a421ac8c59df (ubuntu 24.04)

Severity Package Installed Fixed CVE Title
🟠 HIGH rsync 3.2.7-1ubuntu1.2 3.2.7-1ubuntu1.4 CVE-2026-29518 rsync: TOCTOU symlink race condition allowing local privilege escalation in daemon mode without chroot.
🟠 HIGH rsync 3.2.7-1ubuntu1.2 3.2.7-1ubuntu1.4 CVE-2026-43618 rsync: rsync: Remote memory disclosure via integer overflow in compressed-token decoding

Python

Severity Package Installed Fixed CVE Title
🟠 HIGH python-multipart 0.0.22 0.0.27 CVE-2026-42561 Python-Multipart is a streaming multipart parser for Python. Prior to ...
🟠 HIGH urllib3 2.6.3 2.7.0 CVE-2026-44431 urllib3: urllib3: Information disclosure via cross-origin redirects forwarding sensitive headers
🟠 HIGH urllib3 2.6.3 2.7.0 CVE-2026-44432 urllib3: urllib3: Denial of Service due to excessive HTTP response decompression

cnb/lifecycle/launcher

Severity Package Installed Fixed CVE Title
🟠 HIGH stdlib v1.26.0 1.25.8, 1.26.1 CVE-2026-25679 net/url: Incorrect parsing of IPv6 host literals in net/url
🟠 HIGH stdlib v1.26.0 1.26.1 CVE-2026-27137 crypto/x509: Incorrect enforcement of email constraints in crypto/x509
🟠 HIGH stdlib v1.26.0 1.25.9, 1.26.2 CVE-2026-32280 crypto/x509: crypto/tls: golang: Go: Denial of Service vulnerability in certificate chain building
🟠 HIGH stdlib v1.26.0 1.25.9, 1.26.2 CVE-2026-32281 crypto/x509: golang: Go crypto/x509: Denial of Service via inefficient certificate chain validation
🟠 HIGH stdlib v1.26.0 1.25.9, 1.26.2 CVE-2026-32283 crypto/tls: golang: Go crypto/tls: Denial of Service via multiple TLS 1.3 key update messages
🟠 HIGH stdlib v1.26.0 1.26.2 CVE-2026-33810 crypto/x509: golang: Go crypto/x509: Certificate validation bypass due to incorrect DNS constraint application
🟠 HIGH stdlib v1.26.0 1.25.10, 1.26.3 CVE-2026-33811 net: golang: Go net package: Denial of Service via long CNAME response in LookupCNAME
🟠 HIGH stdlib v1.26.0 1.25.10, 1.26.3 CVE-2026-33814 When processing HTTP/2 SETTINGS frames, transport will enter an infini ...
🟠 HIGH stdlib v1.26.0 1.25.10, 1.26.3 CVE-2026-39820 Well-crafted inputs reaching ParseAddress, ParseAddressList, and Parse ...
🟠 HIGH stdlib v1.26.0 1.25.10, 1.26.3 CVE-2026-39823 CVE-2026-27142 fixed a vulnerability in which URLs were not correctly ...
🟠 HIGH stdlib v1.26.0 1.25.10, 1.26.3 CVE-2026-39825 ReverseProxy can forward queries containing parameters not visible to ...
🟠 HIGH stdlib v1.26.0 1.25.10, 1.26.3 CVE-2026-39826 If a trusted template author were to write a <script> tag containing a ...
🟠 HIGH stdlib v1.26.0 1.25.10, 1.26.3 CVE-2026-39836 Panic in Dial and LookupPort when handling NUL byte on Windows in net
🟠 HIGH stdlib v1.26.0 1.25.10, 1.26.3 CVE-2026-42499 Pathological inputs could cause DoS through consumePhrase when parsing ...

layers/sbom/launch/buildpacksio_lifecycle/launcher/sbom.cdx.json

Severity Package Installed Fixed CVE Title
🟠 HIGH stdlib 1.26.0 1.25.8, 1.26.1 CVE-2026-25679 net/url: Incorrect parsing of IPv6 host literals in net/url
🟠 HIGH stdlib 1.26.0 1.26.1 CVE-2026-27137 crypto/x509: Incorrect enforcement of email constraints in crypto/x509
🟠 HIGH stdlib 1.26.0 1.25.9, 1.26.2 CVE-2026-32280 crypto/x509: crypto/tls: golang: Go: Denial of Service vulnerability in certificate chain building
🟠 HIGH stdlib 1.26.0 1.25.9, 1.26.2 CVE-2026-32281 crypto/x509: golang: Go crypto/x509: Denial of Service via inefficient certificate chain validation
🟠 HIGH stdlib 1.26.0 1.25.9, 1.26.2 CVE-2026-32283 crypto/tls: golang: Go crypto/tls: Denial of Service via multiple TLS 1.3 key update messages
🟠 HIGH stdlib 1.26.0 1.26.2 CVE-2026-33810 crypto/x509: golang: Go crypto/x509: Certificate validation bypass due to incorrect DNS constraint application
🟠 HIGH stdlib 1.26.0 1.25.10, 1.26.3 CVE-2026-33811 net: golang: Go net package: Denial of Service via long CNAME response in LookupCNAME
🟠 HIGH stdlib 1.26.0 1.25.10, 1.26.3 CVE-2026-33814 When processing HTTP/2 SETTINGS frames, transport will enter an infini ...
🟠 HIGH stdlib 1.26.0 1.25.10, 1.26.3 CVE-2026-39820 Well-crafted inputs reaching ParseAddress, ParseAddressList, and Parse ...
🟠 HIGH stdlib 1.26.0 1.25.10, 1.26.3 CVE-2026-39823 CVE-2026-27142 fixed a vulnerability in which URLs were not correctly ...
🟠 HIGH stdlib 1.26.0 1.25.10, 1.26.3 CVE-2026-39825 ReverseProxy can forward queries containing parameters not visible to ...
🟠 HIGH stdlib 1.26.0 1.25.10, 1.26.3 CVE-2026-39826 If a trusted template author were to write a <script> tag containing a ...
🟠 HIGH stdlib 1.26.0 1.25.10, 1.26.3 CVE-2026-39836 Panic in Dial and LookupPort when handling NUL byte on Windows in net
🟠 HIGH stdlib 1.26.0 1.25.10, 1.26.3 CVE-2026-42499 Pathological inputs could cause DoS through consumePhrase when parsing ...

layers/sbom/launch/buildpacksio_lifecycle/launcher/sbom.spdx.json

Severity Package Installed Fixed CVE Title
🟠 HIGH stdlib 1.26.0 1.25.8, 1.26.1 CVE-2026-25679 net/url: Incorrect parsing of IPv6 host literals in net/url
🟠 HIGH stdlib 1.26.0 1.26.1 CVE-2026-27137 crypto/x509: Incorrect enforcement of email constraints in crypto/x509
🟠 HIGH stdlib 1.26.0 1.25.9, 1.26.2 CVE-2026-32280 crypto/x509: crypto/tls: golang: Go: Denial of Service vulnerability in certificate chain building
🟠 HIGH stdlib 1.26.0 1.25.9, 1.26.2 CVE-2026-32281 crypto/x509: golang: Go crypto/x509: Denial of Service via inefficient certificate chain validation
🟠 HIGH stdlib 1.26.0 1.25.9, 1.26.2 CVE-2026-32283 crypto/tls: golang: Go crypto/tls: Denial of Service via multiple TLS 1.3 key update messages
🟠 HIGH stdlib 1.26.0 1.26.2 CVE-2026-33810 crypto/x509: golang: Go crypto/x509: Certificate validation bypass due to incorrect DNS constraint application
🟠 HIGH stdlib 1.26.0 1.25.10, 1.26.3 CVE-2026-33811 net: golang: Go net package: Denial of Service via long CNAME response in LookupCNAME
🟠 HIGH stdlib 1.26.0 1.25.10, 1.26.3 CVE-2026-33814 When processing HTTP/2 SETTINGS frames, transport will enter an infini ...
🟠 HIGH stdlib 1.26.0 1.25.10, 1.26.3 CVE-2026-39820 Well-crafted inputs reaching ParseAddress, ParseAddressList, and Parse ...
🟠 HIGH stdlib 1.26.0 1.25.10, 1.26.3 CVE-2026-39823 CVE-2026-27142 fixed a vulnerability in which URLs were not correctly ...
🟠 HIGH stdlib 1.26.0 1.25.10, 1.26.3 CVE-2026-39825 ReverseProxy can forward queries containing parameters not visible to ...
🟠 HIGH stdlib 1.26.0 1.25.10, 1.26.3 CVE-2026-39826 If a trusted template author were to write a <script> tag containing a ...
🟠 HIGH stdlib 1.26.0 1.25.10, 1.26.3 CVE-2026-39836 Panic in Dial and LookupPort when handling NUL byte on Windows in net
🟠 HIGH stdlib 1.26.0 1.25.10, 1.26.3 CVE-2026-42499 Pathological inputs could cause DoS through consumePhrase when parsing ...

@renovate
renovate Bot force-pushed the renovate/infrabits-ci-pack-digest branch from 24a8f4c to c6aed42 Compare June 2, 2026 01:38
@renovate
renovate Bot merged commit 824f625 into main Jun 2, 2026
2 checks passed
@renovate
renovate Bot deleted the renovate/infrabits-ci-pack-digest branch June 2, 2026 04:36
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants