Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Bump gomplate to 3.11.7 #68

Merged
merged 2 commits into from
Feb 20, 2024
Merged

Bump gomplate to 3.11.7 #68

merged 2 commits into from
Feb 20, 2024

Conversation

xDmitriev
Copy link
Member

No description provided.

@xDmitriev xDmitriev force-pushed the fix/bump-gomplate-version branch from 48751b4 to f551e75 Compare February 18, 2024 09:54
@xDmitriev xDmitriev requested a review from nedvna February 18, 2024 10:16
@xDmitriev xDmitriev force-pushed the fix/bump-gomplate-version branch 5 times, most recently from 9ad2405 to 9322bda Compare February 18, 2024 20:09
Copy link

github-actions bot commented Feb 18, 2024

Overview

Image reference wallarm/node:latest node-x86_64.tar
- digest 6b33a59752f6 453d7fbbffad
- provenance f6ab99b git-a2ce350
- vulnerabilities critical: 2 high: 9 medium: 9 low: 1 unspecified: 1 critical: 0 high: 0 medium: 3 low: 0
- platform linux/amd64 linux/amd64
- size 214 MB 247 MB (+33 MB)
- packages 440 319 (-121)
Base Image alpine:3.18
also known as:
3.18.6
alpine:3.18
also known as:
3.18.6
- vulnerabilities critical: 0 high: 0 medium: 0 low: 0 critical: 0 high: 0 medium: 0 low: 0
Labels (3 changes)
  • ± 3 changed
  • 7 unchanged
 com.wallarm.nginx-docker.versions.aio=4.10.1
 com.wallarm.nginx-docker.versions.alpine=3.18
-com.wallarm.nginx-docker.versions.gomplate=3.11.5
+com.wallarm.nginx-docker.versions.gomplate=3.11.7
 com.wallarm.nginx-docker.versions.nginx=1.24.0
 org.opencontainers.image.documentation=https://docs.wallarm.com/installation/inline/compute-instances/docker/nginx-based
-org.opencontainers.image.revision=git-f6ab99b
+org.opencontainers.image.revision=git-a2ce350
 org.opencontainers.image.source=https://github.com/wallarm/docker-wallarm-node
 org.opencontainers.image.title=Docker official image for Wallarm Node. API security platform agent
 org.opencontainers.image.vendor=Wallarm
-org.opencontainers.image.version=4.10.1-1
+org.opencontainers.image.version=test
Packages and Vulnerabilities (97 package changes and 11 vulnerability changes)
  • ➖ 88 packages removed
  • ♾️ 9 packages changed
  • 303 packages unchanged
  • ✔️ 11 vulnerabilities removed
Changes for packages of type apk (7 changes)
Package Version
wallarm/node:latest
Version
node-x86_64.tar
curl 8.5.0-r0
gomplate 3.11.5-r5
libcurl 8.5.0-r0
libidn2 2.3.4-r1
libunistring 1.1-r1
nghttp2 1.57.0-r0
nghttp2-libs 1.57.0-r0
Changes for packages of type gem (4 changes)
Package Version
wallarm/node:latest
Version
node-x86_64.tar
♾️ cgi 0.2.0 0.4.1
critical: 1 high: 2 medium: 0 low: 0
Removed vulnerabilities (3):
  • critical : CVE--2021--41816
  • high : CVE--2021--33621
  • high : CVE--2021--41819
♾️ date 3.1.0 3.3.4
critical: 0 high: 1 medium: 0 low: 0
Removed vulnerabilities (1):
  • high : CVE--2021--41817
♾️ time 0.1.0 0.3.0
critical: 0 high: 1 medium: 0 low: 0
Removed vulnerabilities (1):
  • high : CVE--2023--28756
♾️ uri 0.10.1 0.13.0
critical: 0 high: 1 medium: 0 low: 0
Removed vulnerabilities (1):
  • high : CVE--2023--28755
Changes for packages of type golang (86 changes)
Package Version
wallarm/node:latest
Version
node-x86_64.tar
cloud.google.com/go 0.102.0
cloud.google.com/go/compute 1.6.1
cloud.google.com/go/iam 0.3.0
cloud.google.com/go/storage 1.22.1
github.com/apparentlymart/go-cidr 1.1.0
github.com/armon/go-metrics 0.4.0
github.com/armon/go-radix 1.0.0
github.com/aws/aws-sdk-go 1.44.206
github.com/aws/aws-sdk-go-v2/internal/endpoints/v2 2.4.5
github.com/aws/smithy-go 1.11.2
github.com/cenkalti/backoff/v3 3.2.2
github.com/docker/libkv 0.2.2-0.20180912205406-458977154600
github.com/dustin/gojson 0.0.0-20160307161227-2e71ec9dd5ad
github.com/emirpasic/gods 1.18.1
github.com/fatih/color 1.13.0
github.com/go-git/gcfg 1.5.0
github.com/go-git/go-billy/v5 5.3.1
github.com/go-git/go-git/v5 5.4.2
critical: 1 high: 1 medium: 0 low: 0
Removed vulnerabilities (2):
  • critical : CVE--2023--49569
  • high : CVE--2023--49568
github.com/golang/groupcache 0.0.0-20210331224755-41bb18bfe9da
github.com/golang/protobuf 1.5.2
github.com/golang/snappy 0.0.4
github.com/google/go-cmp 0.5.8
github.com/google/wire 0.5.0
github.com/googleapis/gax-go/v2 2.4.0
github.com/googleapis/go-type-adapters 1.0.0
github.com/gosimple/slug 1.12.0
github.com/gosimple/unidecode 1.0.1
github.com/hairyhenderson/go-fsimpl 0.0.0-20220529183339-9deae3e35047
github.com/hairyhenderson/gomplate/v3 3.11.5
github.com/hairyhenderson/toml 0.4.2-0.20210923231440-40456b8e66cf
github.com/hairyhenderson/yaml 0.0.0-20220618171115-2d35fca545ce
github.com/hashicorp/consul/api 1.13.0
github.com/hashicorp/errwrap 1.1.0
github.com/hashicorp/go-cleanhttp 0.5.2
github.com/hashicorp/go-hclog 1.2.0
github.com/hashicorp/go-immutable-radix 1.3.1
github.com/hashicorp/go-multierror 1.1.1
github.com/hashicorp/go-plugin 1.4.4
github.com/hashicorp/go-retryablehttp 0.7.1
github.com/hashicorp/go-rootcerts 1.0.2
github.com/hashicorp/go-secure-stdlib/parseutil 0.1.5
github.com/hashicorp/go-sockaddr 1.0.2
github.com/hashicorp/go-uuid 1.0.3
github.com/hashicorp/go-version 1.5.0
github.com/hashicorp/hcl 1.0.0
github.com/hashicorp/serf 0.9.7
github.com/hashicorp/vault/api 1.6.0
github.com/hashicorp/yamux 0.0.0-20211028200310-0bc27b27de87
♾️ github.com/imdario/mergo 0.3.13 0.3.12
github.com/jbenet/go-context 0.0.0-20150711004518-d14ea06fba99
github.com/jmespath/go-jmespath 0.4.0
github.com/joho/godotenv 1.4.0
github.com/kevinburke/ssh_config 1.2.0
github.com/mitchellh/go-homedir 1.1.0
github.com/mitchellh/go-testing-interface 1.14.1
github.com/mitchellh/mapstructure 1.5.0
github.com/oklog/run 1.1.0
github.com/pierrec/lz4 2.6.1+incompatible
github.com/protonmail/go-crypto 0.0.0-20220517143526-88bb52951d5b
github.com/ryanuber/go-glob 1.0.0
github.com/sergi/go-diff 1.2.0
github.com/shopify/ejson 1.3.3
github.com/spf13/afero 1.8.2
github.com/spf13/cobra 1.4.0
github.com/spf13/pflag 1.0.5
github.com/ugorji/go/codec 1.2.7
github.com/xanzy/ssh-agent 0.3.1
github.com/zealic/xignore 0.3.3
go.etcd.io/bbolt 1.3.6
go.opencensus.io 0.23.0
♾️ go.uber.org/atomic 1.9.0 1.11.0
gocloud.dev 0.25.1-0.20220408200107-09b10f7359f7
♾️ golang.org/x/net 0.7.0 0.19.0
critical: 0 high: 1 medium: 0 low: 0
Removed vulnerabilities (1):
  • high : CVE--2023--39325
golang.org/x/oauth2 0.0.0-20220524215830-622c5d57e401
♾️ golang.org/x/sys 0.5.0 0.16.0
golang.org/x/term 0.5.0
golang.org/x/text 0.7.0
golang.org/x/time 0.0.0-20220411224347-583f2d630306
♾️ golang.org/x/xerrors 0.0.0-20220517211312-f3a8303e98df 0.0.0-20200804184101-5ec99f83aff1
google.golang.org/api 0.81.0
google.golang.org/genproto 0.0.0-20220527130721-00d5c0f3be58
google.golang.org/grpc 1.46.2
critical: 0 high: 1 medium: 0 low: 0
Removed vulnerabilities (1):
  • high : GHSA--m425--mq94--257g
google.golang.org/protobuf 1.28.0
gopkg.in/square/go-jose.v2 2.6.0
gopkg.in/warnings.v0 0.1.2
k8s.io/client-go 0.24.1

@xDmitriev xDmitriev force-pushed the fix/bump-gomplate-version branch from 9322bda to 6881123 Compare February 18, 2024 20:22
Copy link

github-actions bot commented Feb 18, 2024

🔍 Vulnerabilities of node-x86_64.tar

📦 Image Reference node-x86_64.tar
digestsha256:453d7fbbffad8a2bd975bfe545545760a9d8d508ea7e8b9eeede18904e76b948
vulnerabilitiescritical: 0 high: 0 medium: 0 low: 0
platformlinux/amd64
size247 MB
packages319
📦 Base Image alpine:3.18
also known as
  • 3.18.6
digestsha256:695ae78b4957fef4e53adc51febd07f5401eb36fcd80fff3e5107a2b4aa42ace
vulnerabilitiescritical: 0 high: 0 medium: 0 low: 0

@xDmitriev xDmitriev force-pushed the fix/bump-gomplate-version branch 3 times, most recently from 3ed5e49 to f87af88 Compare February 19, 2024 13:58
@xDmitriev xDmitriev force-pushed the fix/bump-gomplate-version branch from f87af88 to 63248a7 Compare February 20, 2024 06:28
@xDmitriev xDmitriev merged commit 1a354cb into stable/4.10 Feb 20, 2024
7 checks passed
@xDmitriev xDmitriev deleted the fix/bump-gomplate-version branch February 20, 2024 06:39
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant