Skip to content

Conversation

@catmsred
Copy link
Member

@catmsred catmsred commented Oct 27, 2025

celeborn-0.6 is newly version streamed and existing advisories under version 0.5 need to be updated for the new 0.6 version.

CVEs covered in this PR: GHSA-3p8m-j85q-pgmj, GHSA-fghv-69vj-qj49, GHSA-prj3-ccx8-p6x4, GHSA-j288-q9x7-2f5v, GHSA-h46c-h94j-95f3, GHSA-wf8f-6423-gfxg, GHSA-qh8g-58pp-2wxh, GHSA-xwmg-2g98-w7v9

…3-ccx8-p6x4

celeborn-0.6 is newly version streamed and existing advisories under version 0.5
need to be updated for the new 0.6 version.  netty is brought in by ratis, which
has still not updated to a fixed version of netty.

Relates: wolfi-dev/os#69882, wolfi-dev/os#69911, chainguard-dev/CVE-Dashboard#31614, chainguard-dev/CVE-Dashboard#31634, chainguard-dev/CVE-Dashboard#31623
…f-6423-gfxg, GHSA-qh8g-58pp-2wxh, GHSA-xwmg-2g98-w7v9

celeborn-0.6 is newly version streamed and existing advisories under version 0.5
need to be updated for the new 0.6 version. hadoop is currently brought in at
the most recent version (3.4.2) and all the subsequent transitive dependencies
of hadoop require an upstream fix.

Relates: chainguard-dev/CVE-Dashboard#31631, chainguard-dev/CVE-Dashboard#31625, chainguard-dev/CVE-Dashboard#31629, chainguard-dev/CVE-Dashboard#31627, chainguard-dev/CVE-Dashboard#31621
@dnegreira dnegreira added this pull request to the merge queue Oct 27, 2025
Merged via the queue into wolfi-dev:main with commit 835b737 Oct 27, 2025
4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants