Skip to content

Conversation

@masontikhonov
Copy link

@masontikhonov masontikhonov commented Dec 1, 2025

What

This upgrades dependencies with fixes to some CVE.

Labels

Assign the following labels to the PR:

security - to trigger image scanning in CI build

PR Comments

Add the following comments to the PR:

/e2e - to trigger E2E build

Security Report

Important

Results in this section may be outdated or incomplete.
Please analyze the full scan report for comprehensive details.

Fixed CVEs: 48

🟣 Critical: 1

🔴 High: 1

  • CVE-2024-25621 in github.com/containerd/containerd/v2@v2.1.1 at /usr/local/bin/docker-compose

🟠 Medium: 5

  • GO-2025-3900 in github.com/go-viper/mapstructure/v2@v2.0.0 at /usr/local/bin/docker-compose
  • GO-2025-3787 in github.com/go-viper/mapstructure/v2@v2.0.0 at /usr/local/bin/docker-compose
  • CVE-2025-47914 in golang.org/x/crypto/ssh/agent@v0.37.0 at /usr/local/bin/docker-compose
  • CVE-2025-54388 in github.com/docker/docker@v28.2.2 at /usr/local/bin/docker-compose
  • CVE-2025-64329 in github.com/containerd/containerd/v2@v2.1.1 at /usr/local/bin/docker-compose

🟡 Low: 10

⚪️ Unimportant: 16

⚫ Unassigned: 15

  • CVE-2025-61729 in crypto/x509@1.23.8 at /usr/local/bin/docker-compose
  • CVE-2025-61725 in net/mail@1.23.8 at /usr/local/bin/docker-compose
  • CVE-2025-61723 in encoding/pem@1.23.8 at /usr/local/bin/docker-compose
  • CVE-2025-58188 in crypto/x509@1.23.8 at /usr/local/bin/docker-compose
  • CVE-2025-58187 in crypto/x509@1.23.8 at /usr/local/bin/docker-compose
  • CVE-2025-47913 in golang.org/x/crypto/ssh/agent@v0.37.0 at /usr/local/bin/docker-compose
  • CVE-2025-4673 in net/http@1.23.8 at /usr/local/bin/docker-compose
  • CVE-2025-61727 in crypto/x509@1.23.8 at /usr/local/bin/docker-compose
  • CVE-2025-47906 in os/exec@1.23.8 at /usr/local/bin/docker-compose
  • CVE-2025-61724 in net/textproto@1.23.8 at /usr/local/bin/docker-compose
  • CVE-2025-58189 in crypto/tls@1.23.8 at /usr/local/bin/docker-compose
  • CVE-2025-58186 in net/http@1.23.8 at /usr/local/bin/docker-compose
  • CVE-2025-58185 in encoding/asn1@1.23.8 at /usr/local/bin/docker-compose
  • CVE-2025-47912 in net/url@1.23.8 at /usr/local/bin/docker-compose
  • CVE-2025-58183 in archive/tar@1.23.8 at /usr/local/bin/docker-compose

@masontikhonov masontikhonov self-assigned this Dec 1, 2025
@masontikhonov
Copy link
Author

/e2e

1 similar comment
@masontikhonov
Copy link
Author

/e2e

@masontikhonov
Copy link
Author

/e2e

1 similar comment
@masontikhonov
Copy link
Author

/e2e

@masontikhonov
Copy link
Author

/e2e

@masontikhonov masontikhonov marked this pull request as ready for review December 10, 2025 08:57
@masontikhonov masontikhonov merged commit a28a1e9 into main Dec 12, 2025
5 checks passed
@masontikhonov masontikhonov deleted the CR-32167-security branch December 12, 2025 10:52
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants