Skip to content
This repository was archived by the owner on Jan 7, 2026. It is now read-only.

doc(flyway): GHSA-m494-w24q-6f7w#25388

Merged
catmsred merged 1 commit intowolfi-dev:mainfrom
catmsred:flyway/GHSA-m494-w24q-6f7w
Nov 14, 2025
Merged

doc(flyway): GHSA-m494-w24q-6f7w#25388
catmsred merged 1 commit intowolfi-dev:mainfrom
catmsred:flyway/GHSA-m494-w24q-6f7w

Conversation

@catmsred
Copy link
Copy Markdown
Member

@catmsred catmsred commented Nov 13, 2025

mssql-jdbc version matching issue similar to #25255

Flyway uses mssql-jdbc 12.10 stream [1] and currently uses the fixed version 12.10.2.jre11 [2] at the specified commit [1] for this version of flyway, 11.17.0 (matching between Chainguard [3] and upstream [4]). 12.10.2.jre11 is also the version reported in this advisory file[5].

[1] https://github.com/flyway/flyway/blob/6ac640fac67db05009ea078f105dcc8d95e9e5dd/pom.xml#L174
[2] GHSA-m494-w24q-6f7w
[3] https://github.com/wolfi-dev/os/blob/main/flyway.yaml#L3
[4] https://github.com/flyway/flyway/blob/6ac640fac67db05009ea078f105dcc8d95e9e5dd/pom.xml#L23
[5] https://github.com/wolfi-dev/advisories/blob/main/flyway.advisories.yaml#L66

Relates: https://github.com/chainguard-dev/CVE-Dashboard/issues/36003

mssql-jdbc version matching issue similar to wolfi-dev#25255

Relates: chainguard-dev/CVE-Dashboard#36003
@catmsred catmsred force-pushed the flyway/GHSA-m494-w24q-6f7w branch from a3c53b4 to 4510477 Compare November 13, 2025 20:01
@catmsred catmsred marked this pull request as ready for review November 13, 2025 20:12
@jamie-albert
Copy link
Copy Markdown
Member

  1. version in main is greater than fix version outlined in advisory

@catmsred catmsred requested a review from a team November 14, 2025 11:07
@catmsred catmsred added this pull request to the merge queue Nov 14, 2025
Merged via the queue into wolfi-dev:main with commit 2a29836 Nov 14, 2025
4 checks passed
@catmsred catmsred deleted the flyway/GHSA-m494-w24q-6f7w branch November 14, 2025 11:11
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants