Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

pending-upstream-fix advisory for xh package: GHSA-h97m-ww89-6jmq #11082

Merged

Conversation

mamccorm
Copy link
Member

@mamccorm mamccorm commented Jan 5, 2025

Raising pending-upstream-fix advisory for GHSA-h97m-ww89-6jmq, related to the idna crate. The xh package has multiple dependencies that rrquire different versions of idna.

Attempts at upgrading the oldest (to remediate this CVE), result in additional dependencies needing upgraded (such as cookie_store). Attempting to upgrade those results in similar dependency issues. Will require a fix from upstream.

…te, which we are unable to upgrade to remediate GHSA-h97m-ww89-6jmq

Signed-off-by: Mark McCormick <[email protected]>
@mamccorm mamccorm changed the title pending-upstream-fix advisory for xh package, related to the idna cra… pending-upstream-fix advisory for xh package: GHSA-h97m-ww89-6jmq Jan 5, 2025
@mamccorm mamccorm self-assigned this Jan 5, 2025
@mamccorm mamccorm enabled auto-merge January 5, 2025 01:27
Copy link
Member

@kranurag7 kranurag7 left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

thank you submitted a patch upstream ducaale/xh#397 which should fix this in the new release.

@mamccorm mamccorm added this pull request to the merge queue Jan 5, 2025
Merged via the queue into wolfi-dev:main with commit 2d54ecd Jan 5, 2025
7 checks passed
@mamccorm mamccorm deleted the xh-package-advisory-GHSA-h97m-ww89-6jmq branch January 5, 2025 09:17
mamccorm added a commit to wolfi-dev/os that referenced this pull request Jan 5, 2025
Fixes GHSA-wwq9-3cpr-mm53 vulnerability (hashbrown package).

GHSA-h97m-ww89-6jmq cannot be remediated (idna package). Advisory
created:
 - wolfi-dev/advisories#11082

---------

Signed-off-by: Mark McCormick <[email protected]>
Co-authored-by: octo-sts[bot] <[email protected]>
Co-authored-by: Mark McCormick <[email protected]>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants