Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

melange/0.13.2 package update #30341

Closed
wants to merge 1 commit into from

Conversation

octo-sts[bot]
Copy link
Contributor

@octo-sts octo-sts bot commented Oct 8, 2024

@octo-sts octo-sts bot added request-version-update request for a newer version of a package automated pr labels Oct 8, 2024
Copy link
Contributor

github-actions bot commented Oct 8, 2024

Package melange: Click to expand/collapse

Package melange:
Modified: /usr/bin/melange

Package melange-microvm-init: Click to expand/collapse

Package melange-microvm-init:
Unchanged

malcontent found differences: Click to expand/collapse

Deleted: melange-microvm-init/var/lib/db/sbom/melange-microvm-init-0.13.1-r0.spdx.json [⚠️ MEDIUM]

RISK KEY DESCRIPTION EVIDENCE
-MEDIUM net/download download files downloadLocation
-LOW ref/site/url contains embedded HTTPS URLs https://spdx.org/spdxdocs/chainguard/melange/89539679bab55564abf08c1615e7

Added: melange-microvm-init/var/lib/db/sbom/melange-microvm-init-0.13.2-r0.spdx.json [⚠️ MEDIUM]

RISK KEY DESCRIPTION EVIDENCE
+MEDIUM net/download download files downloadLocation
+LOW ref/site/url contains embedded HTTPS URLs https://spdx.org/spdxdocs/chainguard/melange/03180d6e0a8a84f1b8d79d9867d8

Changed: /tmp/wolfictl-apk-2953385631/melange/usr/bin/melange

Changed: /tmp/wolfictl-apk-2953385631/melange-microvm-init/init

Moved: melange/var/lib/db/sbom/melange-0.13.1-r0.spdx.json -> /tmp/wolfictl-apk-2953385631/melange/var/lib/db/sbom/melange-0.13.2-r0.spdx.json (similarity: 0.99)

@octo-sts octo-sts bot added the bincapz/blocking Bincapz (aka malcontent) scan results detected CRITICALs on the packages. label Oct 8, 2024
Copy link
Contributor Author

octo-sts bot commented Oct 8, 2024

malcontent detected files with a risk score equal or higher than 'CRITICAL': Click to expand/collapse

/tmp/malcontent2009238845/packages/x86_64/melange-0.13.2-r0.apk/usr/bin/melange [🚨 CRITICAL]

RISK KEY DESCRIPTION EVIDENCE
HIGH admin/pip_install Installs software using pip from python pip installb3312fa7e23ee7e4988e056be3f82d19
CRITICAL combo/dropper/shell change dir, fetch file via tor, make it executable, and run it ./b
./configure --prefix
./configure command.
./configure.ac
./dist/
./m
./package.json
./pipe/docker
./pombump-deps.yaml
./pombump-properties.yaml
.onion
cd $
cd /home/build
chmod
curl -L
HIGH ref/path/hidden hidden path in a system directory scallhtml3125Atoilib/bin/.so.

@egibs egibs added the malcontent/reviewed The malcontent findings in this PR have been manually reviewed by security. label Oct 8, 2024
@octo-sts octo-sts bot closed this Oct 8, 2024
Copy link
Contributor Author

octo-sts bot commented Oct 8, 2024

superseded by #30356

@octo-sts octo-sts bot deleted the wolfictl-a0e96648-85c9-43e0-bc16-fbe30b25fcef branch October 9, 2024 00:02
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
automated pr bincapz/blocking Bincapz (aka malcontent) scan results detected CRITICALs on the packages. malcontent/reviewed The malcontent findings in this PR have been manually reviewed by security. request-version-update request for a newer version of a package
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants