Skip to content

Conversation

@catmsred
Copy link
Member

@catmsred catmsred commented Oct 21, 2025

bcpkix-jdk18on is brought in my pulsar. Upstream pulsar fixes this CVE [1], so
bumping pulsar to the version that contains the fix.

[1] apache/pulsar#24650

Relates: https://github.com/chainguard-dev/CVE-Dashboard/issues/31498

@octo-sts octo-sts bot added the bincapz/pass bincapz/pass Bincapz (aka. malcontent) scan didn't detect any CRITICALs on the scanned packages. label Oct 21, 2025
@catmsred catmsred force-pushed the cve_zipkin/GHSA-4cx2-fc23-5wg6 branch from 101b133 to 27f9fbe Compare October 21, 2025 20:29
@catmsred catmsred marked this pull request as ready for review October 21, 2025 20:30
bcpkix-jdk18on is brought in my pulsar.  Upstream pulsar fixes this CVE [1], so
bumping pulsar to the version that contains the fix.

[1] apache/pulsar#24650

Relates: chainguard-dev/CVE-Dashboard#31498
@catmsred catmsred force-pushed the cve_zipkin/GHSA-4cx2-fc23-5wg6 branch from 27f9fbe to c4d6b32 Compare October 21, 2025 22:10
@powersj powersj merged commit 3414f4a into wolfi-dev:main Oct 22, 2025
19 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bincapz/pass bincapz/pass Bincapz (aka. malcontent) scan didn't detect any CRITICALs on the scanned packages.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants