This repository was archived by the owner on Jan 7, 2026. It is now read-only.
neo4j: Raising pending-upstream-fix advisory for: GHSA-qh8g-58pp-2wxh#9165
Merged
hbh7 merged 2 commits intowolfi-dev:mainfrom Nov 20, 2024
Merged
neo4j: Raising pending-upstream-fix advisory for: GHSA-qh8g-58pp-2wxh#9165hbh7 merged 2 commits intowolfi-dev:mainfrom
pending-upstream-fix advisory for: GHSA-qh8g-58pp-2wxh#9165hbh7 merged 2 commits intowolfi-dev:mainfrom
Conversation
…ndencies: jetty-http. This relates to GHSA-qh8g-58pp-2wxh, which we are unable to remediate ourselves. Will require a fix upstream. Signed-off-by: Mark McCormick <mark.mccormick@chainguard.dev>
Signed-off-by: Mark McCormick <mark.mccormick@chainguard.dev>
philroche
approved these changes
Nov 20, 2024
mamccorm
added a commit
to wolfi-dev/os
that referenced
this pull request
Nov 20, 2024
Unfortunately, not all the CVEs [listed in this PR (initially)](20cc95d), can be remediated. Removed those which could not, and filed an advisory for the other: - wolfi-dev/advisories#9165 Note, there is a separate `netty-common` finding which is now being picked up by the scanners but wasn't included in this PR. I am unable to find the source for this, as there is no netty-common dep defined in any pom.xml's that I can see. Couldn't easily pin this one down. But not holding up getting the other fix merged and will address separately. --------------- neo4j/5.24.2-r0: fix GHSA-735f-pc8j-v9w8/GHSA-qh8g-58pp-2wxh/GHSA-g8m5-722r-8whq/ Advisory data: https://github.com/wolfi-dev/advisories/blob/main/neo4j.advisories.yaml --------- Signed-off-by: Mark McCormick <mark.mccormick@chainguard.dev> Signed-off-by: Jason Hall <jason@chainguard.dev> Co-authored-by: octo-sts[bot] <157150467+octo-sts@users.noreply.github.com> Co-authored-by: Mark McCormick <mark.mccormick@chainguard.dev> Co-authored-by: Jason Hall <jason@chainguard.dev>
github-merge-queue bot
pushed a commit
that referenced
this pull request
Dec 28, 2024
* Adv(Pending-upstream): advisory has been coppied from #9165 this is a renamed package so all the advisory should be same Signed-off-by: Debasish Biswas <debasishbsws.dev@gmail.com> * Yam lint Signed-off-by: Debasish Biswas <debasishbsws.dev@gmail.com> --------- Signed-off-by: Debasish Biswas <debasishbsws.dev@gmail.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to subscribe to this conversation on GitHub.
Already have an account?
Sign in.
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Related CVE remediation PR: wolfi-dev/os#32618
Unfortunately we are unable to remediate this CVE, and we'll require a fix to be applied upstream. Raising as
pending-upstream-fix. See advisory description in this PR for more information.