Skip to content

Conversation

@brianmcarey
Copy link
Member

@octo-sts octo-sts bot added the bincapz/pass bincapz/pass Bincapz (aka. malcontent) scan didn't detect any CRITICALs on the scanned packages. label Jan 7, 2026
@brianmcarey
Copy link
Member Author

The CI CVE scan failed to scan but here is a local scan of the presubmit APKs:

wolfictl scan open-webui-*
🔎 Scanning "open-webui-0.6.43-r1-aarch64.apk"
├── 📄 /usr/share/open-webui/lib/python3.11/site-packages/ecdsa-0.19.1.dist-info/METADATA
│       📦 ecdsa 0.19.1 (python)
│           High CVE-2024-23342 GHSA-wj6h-64fc-37mp
├── 📄 /usr/share/open-webui/lib/python3.11/site-packages/open_webui/frontend/pyodide/fonttools-4.56.0-py3-none-any.whl
│       📦 fonttools 4.56.0 (python)
│           Medium CVE-2025-66034 GHSA-768j-98cg-p3fv fixed in 4.60.2
└── 📄 /usr/share/open-webui/lib/python3.11/site-packages/open_webui/frontend/pyodide/urllib3-2.5.0-py3-none-any.whl
        📦 urllib3 2.5.0 (python)
            High CVE-2025-66471 GHSA-2xpw-w6gg-jr37 fixed in 2.6.0
            High CVE-2025-66418 GHSA-gm62-xv2j-4w53 fixed in 2.6.0

🔎 Scanning "open-webui-0.6.43-r1-x86_64.apk"
├── 📄 /usr/share/open-webui/lib/python3.11/site-packages/ecdsa-0.19.1.dist-info/METADATA
│       📦 ecdsa 0.19.1 (python)
│           High CVE-2024-23342 GHSA-wj6h-64fc-37mp
├── 📄 /usr/share/open-webui/lib/python3.11/site-packages/open_webui/frontend/pyodide/fonttools-4.56.0-py3-none-any.whl
│       📦 fonttools 4.56.0 (python)
│           Medium CVE-2025-66034 GHSA-768j-98cg-p3fv fixed in 4.60.2
└── 📄 /usr/share/open-webui/lib/python3.11/site-packages/open_webui/frontend/pyodide/urllib3-2.5.0-py3-none-any.whl
        📦 urllib3 2.5.0 (python)
            High CVE-2025-66471 GHSA-2xpw-w6gg-jr37 fixed in 2.6.0
            High CVE-2025-66418 GHSA-gm62-xv2j-4w53 fixed in 2.6.0

🔎 Scanning "open-webui-compat-0.6.43-r1-aarch64.apk"
✅ No vulnerabilities found
🔎 Scanning "open-webui-compat-0.6.43-r1-x86_64.apk"
✅ No vulnerabilities found

The vulnerabilities in question are no longer present

@Ankush-Pathak Ankush-Pathak merged commit e26eebf into wolfi-dev:main Jan 8, 2026
18 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bincapz/pass bincapz/pass Bincapz (aka. malcontent) scan didn't detect any CRITICALs on the scanned packages.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants