Skip to content

Conversation

@octo-sts
Copy link
Contributor

@octo-sts octo-sts bot commented Oct 21, 2024

Signed-off-by: wolfi-bot <121097084+wolfi-bot@users.noreply.github.com>
@octo-sts octo-sts bot added request-version-update request for a newer version of a package automated pr labels Oct 21, 2024
@github-actions
Copy link
Contributor

Package frp: Click to expand/collapse

Package frp:

.PKGINFO metadata:

  (
  	"""
  	# Generated by melange
  	pkgname = frp
- 	pkgver = 0.60.0-r1
+ 	pkgver = 0.61.0-r0
  	arch = x86_64
- 	size = 33609760
+ 	size = 33610900
  	origin = frp
  	pkgdesc = A fast reverse proxy to help you expose a local server behind a NAT or firewall to the internet.
  	url = 
- 	commit = 6ee77b0223e70b991c042ee0325a21aa6a6bb9b9
- 	builddate = 1726705567
+ 	commit = be2a7ed07ab69e83daf3ee728d8b71f5172044a1
+ 	builddate = 1729554979
  	license = Apache-2.0
- 	provides = cmd:frpc=0.60.0-r1
- 	provides = cmd:frps=0.60.0-r1
- 	datahash = f7d56b4857310510944e5acb11f7333d9683a5fba783859648580a9be9110519
+ 	provides = cmd:frpc=0.61.0-r0
+ 	provides = cmd:frps=0.61.0-r0
+ 	datahash = 0f1919d4110a8c83113bcd96a0c6bd8e04509d2559597ee4a58d3d73c91a439a
  	"""
  )

Modified: /usr/bin/frpc
Modified: /usr/bin/frps

@octo-sts octo-sts bot added the bincapz/blocking Bincapz (aka malcontent) scan results detected CRITICALs on the packages. label Oct 22, 2024
@octo-sts
Copy link
Contributor Author

octo-sts bot commented Oct 22, 2024

malcontent detected files with a risk score equal or higher than 'CRITICAL': Click to expand/collapse

/tmp/malcontent2594291478/packages/x86_64/frp-0.61.0-r0.apk/usr/bin/frpc [🚨 CRITICAL]

RISK KEY DESCRIPTION EVIDENCE
CRITICAL 3P/JPCERT/frp/str Detect fast reverse proxy (frp), by JPCERT/CC Incident Response Group json:"authenticate_new_work_conns"
json:"bind_addr"
json:"health_check_interval_s"
json:"log_way"
json:"sk"
json:"token_type,omitempty"

/tmp/malcontent2594291478/packages/x86_64/frp-0.61.0-r0.apk/usr/bin/frps [🚨 CRITICAL]

RISK KEY DESCRIPTION EVIDENCE
CRITICAL 3P/JPCERT/frp/str Detect fast reverse proxy (frp), by JPCERT/CC Incident Response Group json:"authenticate_new_work_conns"
json:"bind_addr"
json:"detailed_errors_to_client"
json:"health_check_interval_s"
json:"log_way"
json:"oidc_skip_expiry_check"
json:"proxy_name"
json:"sk"
json:"token_type,omitempty"
CRITICAL 3P/elastic/proxy/frp Detects Linux Proxy Frp (Linux.Proxy.Frp), by Elastic Security frp/client/proxy/proxy_manager.go
frp/cmd/frps/main.go
github.com/fatedier/frp/server/proxy
json:"remote_port"
remote_addr

@egibs egibs added the malcontent/reviewed The malcontent findings in this PR have been manually reviewed by security. label Oct 22, 2024
@philroche philroche self-assigned this Oct 23, 2024
@philroche
Copy link
Member

Changes summary:
Total files changed: 19

Total changes: 176
Total additions: 125
Total deletions: 51

Total commits: 8

GitHub compare URL: fatedier/frp@ccfe8c9...4bbec09

@philroche philroche merged commit a3a88f3 into main Oct 23, 2024
@philroche philroche deleted the wolfictl-35e0877d-6c88-484e-9caa-c875bae7d204 branch October 23, 2024 10:48
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

automated pr bincapz/blocking Bincapz (aka malcontent) scan results detected CRITICALs on the packages. malcontent/reviewed The malcontent findings in this PR have been manually reviewed by security. request-version-update request for a newer version of a package

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants