Skip to content

Backport of suppressing alpine CVEs as there is no fix yet into release/1.21.x#22279

Merged
nitin-sachdev-29 merged 1 commit intorelease/1.21.xfrom
backport/nitin/cve-suppress/highly-expert-squid
Apr 18, 2025
Merged

Backport of suppressing alpine CVEs as there is no fix yet into release/1.21.x#22279
nitin-sachdev-29 merged 1 commit intorelease/1.21.xfrom
backport/nitin/cve-suppress/highly-expert-squid

Conversation

@hc-github-team-consul-core
Copy link
Copy Markdown
Collaborator

Backport

This PR is auto-generated from #22278 to be assessed for backporting due to the inclusion of the label backport/1.21.

The below text is copied from the body of the original PR.


Description

Suppressing following alpine CVEs as there is no fix yet:

CVE-2024-53427 from Alpine Linux's Security Issue Tracker in jq@1.7.1-r0

CVE-2025-31498 from Alpine Linux's Security Issue Tracker in c-ares@1.34.3-r0

CVE-2025-30258 from Alpine Linux's Security Issue Tracker in gnupg@2.4.7-r0

CVE-2025-31498 from Alpine Linux's Security Issue Tracker in c-ares@1.34.3-r0

CVE-2025-30258 from Alpine Linux's Security Issue Tracker in gnupg@2.4.7-r0

CVE-2024-53427 from Alpine Linux's Security Issue Tracker in jq@1.7.1-r0

Testing & Reproduction steps

Links

PR Checklist

  • updated test coverage
  • external facing docs updated
  • appropriate backport labels added
  • not a security concern

Overview of commits

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Auto approved Consul Bot automated PR

@nitin-sachdev-29 nitin-sachdev-29 enabled auto-merge (squash) April 18, 2025 06:53
Copy link
Copy Markdown
Contributor

@nitin-sachdev-29 nitin-sachdev-29 left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@nitin-sachdev-29 nitin-sachdev-29 merged commit fe1fe35 into release/1.21.x Apr 18, 2025
184 of 195 checks passed
@nitin-sachdev-29 nitin-sachdev-29 deleted the backport/nitin/cve-suppress/highly-expert-squid branch April 18, 2025 07:38
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants