Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
68 changes: 21 additions & 47 deletions images/ci-tools/.trivyignore.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -26,7 +26,7 @@ vulnerabilities:
1.26.1) — offline lint/format tools with no untrusted network or
certificate input, so practical risk is negligible. Tracking: #96.
Remove once both ship builds on Go >= 1.25.9 or 1.26.2.
expired_at: 2026-07-21
expired_at: 2026-09-01

- id: CVE-2026-32281
statement: >-
Expand All @@ -35,7 +35,7 @@ vulnerabilities:
1.26.1) — offline lint/format tools with no untrusted network or
certificate input, so practical risk is negligible. Tracking: #96.
Remove once both ship builds on Go >= 1.25.9 or 1.26.2.
expired_at: 2026-07-21
expired_at: 2026-09-01

- id: CVE-2026-32283
statement: >-
Expand All @@ -44,7 +44,7 @@ vulnerabilities:
1.26.1) — offline lint/format tools that open no TLS sessions to
untrusted peers, so practical risk is negligible. Tracking: #96.
Remove once both ship builds on Go >= 1.25.9 or 1.26.2.
expired_at: 2026-07-21
expired_at: 2026-09-01

- id: CVE-2026-33810
statement: >-
Expand All @@ -54,7 +54,7 @@ vulnerabilities:
no X.509 chains against untrusted input, so practical risk is
negligible. Tracking: #96. Remove once both ship builds on Go >=
1.26.2.
expired_at: 2026-07-21
expired_at: 2026-09-01

- id: CVE-2026-33811
statement: >-
Expand All @@ -63,7 +63,7 @@ vulnerabilities:
shfmt v3.13.1 (Go 1.26.1) — offline lint/format tools that resolve no
untrusted hostnames, so practical risk is negligible. Tracking: #96.
Remove once both ship builds on Go >= 1.25.10 or 1.26.3.
expired_at: 2026-07-21
expired_at: 2026-09-01

- id: CVE-2026-33814
statement: >-
Expand All @@ -72,7 +72,7 @@ vulnerabilities:
(Go 1.26.1) — offline lint/format tools that serve no HTTP/2 to
untrusted peers, so practical risk is negligible. Tracking: #96.
Remove once both ship builds on Go >= 1.25.10 or 1.26.3.
expired_at: 2026-07-21
expired_at: 2026-09-01

- id: CVE-2026-39820
statement: >-
Expand All @@ -81,7 +81,17 @@ vulnerabilities:
v3.13.1 (Go 1.26.1) — offline lint/format tools that parse no
untrusted mail addresses, so practical risk is negligible. Tracking:
#96. Remove once both ship builds on Go >= 1.25.10 or 1.26.3.
expired_at: 2026-07-21
expired_at: 2026-09-01

- id: CVE-2026-39822
statement: >-
os: Go os.Root symlink following allows directory traversal, fixed in
Go 1.25.12 / 1.26.5. Affects actionlint v1.7.12 and shfmt v3.13.1 (Go
1.26.1) and yq v4.53.3 (Go 1.26.4) — offline lint/format/YAML tools
that confine no untrusted filesystem paths via os.Root, so practical
risk is negligible. Tracking: #96. Remove once all three ship builds
on Go >= 1.25.12 or 1.26.5.
expired_at: 2026-09-01

- id: CVE-2026-39836
statement: >-
Expand All @@ -90,7 +100,7 @@ vulnerabilities:
v3.13.1 (Go 1.26.1) — offline lint/format tools that dial no
untrusted addresses, so practical risk is negligible. Tracking: #96.
Remove once both ship builds on Go >= 1.25.10 or 1.26.3.
expired_at: 2026-07-21
expired_at: 2026-09-01

- id: CVE-2026-42499
statement: >-
Expand All @@ -99,25 +109,7 @@ vulnerabilities:
1.26.1) — offline lint/format tools that parse no untrusted mail
addresses, so practical risk is negligible. Tracking: #96. Remove
once both ship builds on Go >= 1.25.10 or 1.26.3.
expired_at: 2026-07-21

- id: CVE-2026-39823
statement: >-
net/url incomplete fix for CVE-2026-27142 (URLs not parsed/escaped
safely), fixed in Go 1.25.10 / 1.26.3. Affects actionlint v1.7.12 and
shfmt v3.13.1 (Go 1.26.1) — offline lint/format tools that parse no
untrusted URLs, so practical risk is negligible. Tracking: #96.
Remove once both ship builds on Go >= 1.25.10 or 1.26.3.
expired_at: 2026-07-21

- id: CVE-2026-39825
statement: >-
net/http/httputil ReverseProxy forwards unsanitized query parameters,
fixed in Go 1.25.10 / 1.26.3. Affects actionlint v1.7.12 and shfmt
v3.13.1 (Go 1.26.1) — offline lint/format tools that run no reverse
proxy, so practical risk is negligible. Tracking: #96. Remove once
both ship builds on Go >= 1.25.10 or 1.26.3.
expired_at: 2026-07-21
expired_at: 2026-09-01

- id: CVE-2026-42504
statement: >-
Expand All @@ -126,7 +118,7 @@ vulnerabilities:
(Go 1.26.1) — offline lint/format tools that decode no untrusted MIME
headers, so practical risk is negligible. Tracking: #96. Remove once
both ship builds on Go >= 1.25.11 or 1.26.4.
expired_at: 2026-07-21
expired_at: 2026-09-01

- id: CVE-2026-27145
statement: >-
Expand All @@ -136,22 +128,4 @@ vulnerabilities:
lint/format tools that verify no certificates against untrusted input,
so practical risk is negligible. Tracking: #96. Remove once both ship
builds on Go >= 1.25.11 or 1.26.4.
expired_at: 2026-07-21

- id: CVE-2026-32316
statement: >-
jq: DoS or potential arbitrary code execution via crafted input, fixed
in 1.6-2.1+deb12u2. Affects jq 1.6-2.1+deb12u1 — the deb12u2 build is
not yet in the Debian mirror, so a rebuild still installs deb12u1. jq
runs only on trusted CI inputs here, so practical risk is negligible.
Tracking: #96. Remove once deb12u2 reaches the bookworm mirror.
expired_at: 2026-08-19

- id: CVE-2026-40164
statement: >-
jq: DoS via a crafted JSON object, fixed in 1.6-2.1+deb12u2. Affects jq
1.6-2.1+deb12u1 — the deb12u2 build is not yet in the Debian mirror, so
a rebuild still installs deb12u1. jq runs only on trusted CI inputs
here, so practical risk is negligible. Tracking: #96. Remove once
deb12u2 reaches the bookworm mirror.
expired_at: 2026-08-19
expired_at: 2026-09-01
6 changes: 3 additions & 3 deletions images/ci-tools/versions.lock
Original file line number Diff line number Diff line change
@@ -1,4 +1,4 @@
NPM_VERSION=11.18.0
NPM_VERSION=12.0.1
SHFMT_VERSION=v3.13.1
SHFMT_SHA256_AMD64=fb096c5d1ac6beabbdbaa2874d025badb03ee07929f0c9ff67563ce8c75398b1
SHFMT_SHA256_ARM64=32d92acaa5cd8abb29fc49dac123dc412442d5713967819d8af2c29f1b3857c7
Expand All @@ -11,8 +11,8 @@ HADOLINT_SHA256_ARM64=331f1d3511b84a4f1e3d18d52fec284723e4019552f4f47b19322a53ce
YQ_VERSION=v4.53.3
YQ_SHA256_AMD64=fa52a4e758c63d38299163fbdd1edfb4c4963247918bf9c1c5d31d84789eded4
YQ_SHA256_ARM64=578648e463a11c1b6db6010cbf41eafed6bee79466fcffa1bb446672cf7945ea
MARKDOWNLINT_CLI2_VERSION=0.23.0
BIOME_VERSION=2.5.2
MARKDOWNLINT_CLI2_VERSION=0.23.1
BIOME_VERSION=2.5.4
STYLELINT_VERSION=17.14.0
LUACHECK_VERSION=1.2.0-1
BUSTED_VERSION=2.3.0-1
Expand Down