Skip to content

Merge branch 'main' into cve-flux-source-controller-1.6.2-r1-b7517d07…

00af230
Select commit
Loading
Failed to load commit list.
Merged

flux-source-controller/1.6.2-r1: cve remediation #58640

Merge branch 'main' into cve-flux-source-controller-1.6.2-r1-b7517d07…
00af230
Select commit
Loading
Failed to load commit list.
Octo STS / ci-diff-report succeeded Jul 10, 2025 in 0s

Package diff

Package diff

Details

Package Diffs

aarch64/flux-source-controller-1.6.2-r1.apk -> aarch64/flux-source-controller-1.6.2-r2.apk

📦 Package diff:

  &apk.Package{
  	Name:        "flux-source-controller",
- 	Version:     "1.6.2-r1",
+ 	Version:     "1.6.2-r2",
  	Arch:        "aarch64",
  	Description: "The GitOps Toolkit source management component",
  	... // 2 identical fields
  	Maintainer: "wolfi",
  	URL:        "",
  	Checksum: []uint8{
- 		0x18, 0x72, 0x41, 0x81, 0x21, 0xfa, 0xf3, 0x14, 0x8f, 0x2a, 0xbe, 0xa7, 0x54, 0x6c, 0xbc, 0x09, // -|.rA.!....*..Tl..|
- 		0x7c, 0x27, 0x35, 0xe7,                                                                         // -||'5.|
+ 		0xab, 0xc0, 0x82, 0xf5, 0x5e, 0x96, 0x24, 0x29, 0x03, 0x01, 0xb0, 0x87, 0xd6, 0xfd, 0x2a, 0xa8, // +|....^.$)......*.|
+ 		0x15, 0xf3, 0x7f, 0x34,                                                                         // +|...4|
  	},
  	Dependencies:     {"merged-usrsbin", "wolfi-baselayout"},
- 	Provides:         []string{"cmd:source-controller=1.6.2-r1"},
+ 	Provides:         []string{"cmd:source-controller=1.6.2-r2"},
  	InstallIf:        nil,
- 	Size:             39165669,
+ 	Size:             39052271,
- 	InstalledSize:    141996485,
+ 	InstalledSize:    141385463,
  	ProviderPriority: 0,
- 	BuildTime:        s"2025-06-28 11:21:54 +0000 UTC",
+ 	BuildTime:        s"2025-07-10 08:30:07 +0000 UTC",
- 	BuildDate:        1751109714,
+ 	BuildDate:        1752136207,
  	RepoCommit: strings.Join({
- 		"f754445ff42a1bdaa045259910ef85075a165361",
+ 		"4f40198b061c61e0df0ff31c0abf9c5457fec52a",
  	}, ""),
  	Replaces: nil,
  	DataHash: "",
  }

➕ Added:

  • var/lib/db/sbom/flux-source-controller-1.6.2-r2.spdx.json

➖ Removed:

  • var/lib/db/sbom/flux-source-controller-1.6.2-r1.spdx.json

🔺 Changed:

.PKGINFO
- -rw-r--r-- 483 2025-06-28 11:21:54 .PKGINFO
+ -rw-r--r-- 483 2025-07-10 08:30:07 .PKGINFO
.melange.yaml
- -rw-r--r-- 47459 2025-06-28 11:21:54 .melange.yaml
+ -rw-r--r-- 47492 2025-07-10 08:30:07 .melange.yaml
usr/bin/source-controller
- -rwxr-xr-x 141964616 2025-06-28 11:21:54 source-controller
-   APK-TOOLS.checksum.SHA1: "27a339414fc346efa68dbc203d48a6411779ef43"
+ -rwxr-xr-x 141353240 2025-07-10 08:30:07 source-controller
+   APK-TOOLS.checksum.SHA1: "f043ab954bf7944f7e8617df527dc531bafaf90c"

aarch64/flux-source-controller-bitnami-compat-1.6.2-r1.apk -> aarch64/flux-source-controller-bitnami-compat-1.6.2-r2.apk

📦 Package diff:

  &apk.Package{
  	Name:        "flux-source-controller-bitnami-compat",
- 	Version:     "1.6.2-r1",
+ 	Version:     "1.6.2-r2",
  	Arch:        "aarch64",
  	Description: "Compatibility package for usage with the Bitnami helm chart.",
  	... // 2 identical fields
  	Maintainer: "wolfi",
  	URL:        "",
  	Checksum: []uint8{
- 		0x9d, 0xdd, 0xe8, 0xf9, 0x91, 0x0b, 0xa2, 0xa4, 0x1f, 0x84, 0xac, 0xf9, 0x41, 0xd4, 0xe3, 0xaf, // -|............A...|
- 		0x85, 0x75, 0x4c, 0x42,                                                                         // -|.uLB|
+ 		0x04, 0xd5, 0x1c, 0x64, 0xa0, 0xe9, 0xd9, 0xec, 0x34, 0x09, 0xcf, 0xbd, 0x4c, 0xa3, 0xe4, 0x7e, // +|...d....4...L..~|
+ 		0xbc, 0x58, 0x43, 0xcc,                                                                         // +|.XC.|
  	},
  	Dependencies:     {"merged-usrsbin", "wolfi-baselayout"},
  	Provides:         nil,
  	InstallIf:        nil,
- 	Size:             10872,
+ 	Size:             10929,
- 	InstalledSize:    40192,
+ 	InstalledSize:    40546,
  	ProviderPriority: 0,
- 	BuildTime:        s"2025-06-28 11:21:54 +0000 UTC",
+ 	BuildTime:        s"2025-07-10 08:30:07 +0000 UTC",
- 	BuildDate:        1751109714,
+ 	BuildDate:        1752136207,
  	RepoCommit: strings.Join({
- 		"f754445ff42a1bdaa045259910ef85075a165361",
+ 		"4f40198b061c61e0df0ff31c0abf9c5457fec52a",
  	}, ""),
  	Replaces: nil,
  	DataHash: "",
  }

➕ Added:

  • var/lib/db/sbom/flux-source-controller-bitnami-compat-1.6.2-r2.spdx.json

➖ Removed:

  • var/lib/db/sbom/flux-source-controller-bitnami-compat-1.6.2-r1.spdx.json

🔺 Changed:

.PKGINFO
- -rw-r--r-- 466 2025-06-28 11:21:54 .PKGINFO
+ -rw-r--r-- 466 2025-07-10 08:30:07 .PKGINFO
.melange.yaml
- -rw-r--r-- 47459 2025-06-28 11:21:54 .melange.yaml
+ -rw-r--r-- 47492 2025-07-10 08:30:07 .melange.yaml

aarch64/flux-source-controller-iamguarded-compat-1.6.2-r1.apk -> aarch64/flux-source-controller-iamguarded-compat-1.6.2-r2.apk

📦 Package diff:

  &apk.Package{
  	Name:        "flux-source-controller-iamguarded-compat",
- 	Version:     "1.6.2-r1",
+ 	Version:     "1.6.2-r2",
  	Arch:        "aarch64",
  	Description: "compat package for iamguarded",
  	... // 2 identical fields
  	Maintainer: "wolfi",
  	URL:        "",
  	Checksum: []uint8{
- 		0x26, 0x31, 0x1d, 0xfe, 0xa2, 0x2f, 0x99, 0xaf, 0x78, 0xac, 0x05, 0x01, 0x7b, 0x75, 0xa0, 0x34, // -|&1.../..x...{u.4|
- 		0xf9, 0xb2, 0xf8, 0x0e,                                                                         // -|....|
+ 		0xb5, 0x01, 0xc4, 0x6d, 0x29, 0xd8, 0xc5, 0x7d, 0x16, 0x2f, 0xc3, 0x9d, 0x07, 0xd4, 0xc0, 0x20, // +|...m)..}./..... |
+ 		0x8f, 0x61, 0x9d, 0xaa,                                                                         // +|.a..|
  	},
  	Dependencies:     nil,
- 	Provides:         []string{"cmd:run-script=1.6.2-r1"},
+ 	Provides:         []string{"cmd:run-script=1.6.2-r2"},
  	InstallIf:        nil,
- 	Size:             12015,
+ 	Size:             12076,
- 	InstalledSize:    54128,
+ 	InstalledSize:    54482,
  	ProviderPriority: 0,
- 	BuildTime:        s"2025-06-28 11:21:54 +0000 UTC",
+ 	BuildTime:        s"2025-07-10 08:30:07 +0000 UTC",
- 	BuildDate:        1751109714,
+ 	BuildDate:        1752136207,
  	RepoCommit: strings.Join({
- 		"f754445ff42a1bdaa045259910ef85075a165361",
+ 		"4f40198b061c61e0df0ff31c0abf9c5457fec52a",
  	}, ""),
  	Replaces: nil,
  	DataHash: "",
  }

➕ Added:

  • var/lib/db/sbom/flux-source-controller-iamguarded-compat-1.6.2-r2.spdx.json

➖ Removed:

  • var/lib/db/sbom/flux-source-controller-iamguarded-compat-1.6.2-r1.spdx.json

🔺 Changed:

.PKGINFO
- -rw-r--r-- 423 2025-06-28 11:21:54 .PKGINFO
+ -rw-r--r-- 423 2025-07-10 08:30:07 .PKGINFO
.melange.yaml
- -rw-r--r-- 47459 2025-06-28 11:21:54 .melange.yaml
+ -rw-r--r-- 47492 2025-07-10 08:30:07 .melange.yaml
opt/iamguarded/LICENSE-Chainguard
- -rw-r--r-- 209 2025-06-28 11:21:54 LICENSE-Chainguard
+ -rw-r--r-- 209 2025-07-10 08:30:07 LICENSE-Chainguard
opt/iamguarded/NOTICE
- -rw-r--r-- 987 2025-06-28 11:21:54 NOTICE
+ -rw-r--r-- 987 2025-07-10 08:30:07 NOTICE
usr/bin/run-script
- -rwxr-xr-x 431 2025-06-28 11:21:54 run-script
+ -rwxr-xr-x 431 2025-07-10 08:30:07 run-script

x86_64/flux-source-controller-1.6.2-r1.apk -> x86_64/flux-source-controller-1.6.2-r2.apk

📦 Package diff:

  &apk.Package{
  	Name:        "flux-source-controller",
- 	Version:     "1.6.2-r1",
+ 	Version:     "1.6.2-r2",
  	Arch:        "x86_64",
  	Description: "The GitOps Toolkit source management component",
  	... // 2 identical fields
  	Maintainer: "wolfi",
  	URL:        "",
  	Checksum: []uint8{
- 		0xb3, 0xbb, 0x5d, 0x1a, 0x92, 0xfd, 0xcf, 0x5c, 0x3d, 0x70, 0x2d, 0x99, 0x5a, 0xe2, 0x49, 0x94, // -|..]....\=p-.Z.I.|
- 		0xa5, 0x49, 0x9e, 0xc3,                                                                         // -|.I..|
+ 		0x56, 0x53, 0xe8, 0x02, 0x16, 0x9d, 0xbd, 0x74, 0x02, 0xaa, 0xae, 0x11, 0x93, 0xc0, 0xd2, 0x81, // +|VS.....t........|
+ 		0x7b, 0x15, 0x40, 0xb8,                                                                         // +|{.@.|
  	},
  	Dependencies:     {"merged-usrsbin", "wolfi-baselayout"},
- 	Provides:         []string{"cmd:source-controller=1.6.2-r1"},
+ 	Provides:         []string{"cmd:source-controller=1.6.2-r2"},
  	InstallIf:        nil,
- 	Size:             42510040,
+ 	Size:             42355413,
- 	InstalledSize:    147458188,
+ 	InstalledSize:    146807982,
  	ProviderPriority: 0,
- 	BuildTime:        s"2025-06-28 11:21:54 +0000 UTC",
+ 	BuildTime:        s"2025-07-10 08:30:07 +0000 UTC",
- 	BuildDate:        1751109714,
+ 	BuildDate:        1752136207,
  	RepoCommit: strings.Join({
- 		"f754445ff42a1bdaa045259910ef85075a165361",
+ 		"4f40198b061c61e0df0ff31c0abf9c5457fec52a",
  	}, ""),
  	Replaces: nil,
  	DataHash: "",
  }

➕ Added:

  • var/lib/db/sbom/flux-source-controller-1.6.2-r2.spdx.json

➖ Removed:

  • var/lib/db/sbom/flux-source-controller-1.6.2-r1.spdx.json

🔺 Changed:

.PKGINFO
- -rw-r--r-- 482 2025-06-28 11:21:54 .PKGINFO
+ -rw-r--r-- 482 2025-07-10 08:30:07 .PKGINFO
.melange.yaml
- -rw-r--r-- 47423 2025-06-28 11:21:54 .melange.yaml
+ -rw-r--r-- 47456 2025-07-10 08:30:07 .melange.yaml
usr/bin/source-controller
- -rwxr-xr-x 147426320 2025-06-28 11:21:54 source-controller
-   APK-TOOLS.checksum.SHA1: "022f5a6661c2c2db8ec6cccc3d5f69a601a1a57d"
+ -rwxr-xr-x 146775760 2025-07-10 08:30:07 source-controller
+   APK-TOOLS.checksum.SHA1: "48216eded33e8b9965c11a1712f2517c814409df"

x86_64/flux-source-controller-bitnami-compat-1.6.2-r1.apk -> x86_64/flux-source-controller-bitnami-compat-1.6.2-r2.apk

📦 Package diff:

  &apk.Package{
  	Name:        "flux-source-controller-bitnami-compat",
- 	Version:     "1.6.2-r1",
+ 	Version:     "1.6.2-r2",
  	Arch:        "x86_64",
  	Description: "Compatibility package for usage with the Bitnami helm chart.",
  	... // 2 identical fields
  	Maintainer: "wolfi",
  	URL:        "",
  	Checksum: []uint8{
- 		0xab, 0x09, 0xa7, 0xcb, 0xf9, 0x2e, 0x54, 0x27, 0x1c, 0xf3, 0x10, 0x21, 0xad, 0x3c, 0xe0, 0x66, // -|......T'...!.<.f|
- 		0x09, 0xf9, 0x8f, 0xb3,                                                                         // -|....|
+ 		0x1c, 0x0a, 0x95, 0x52, 0xbf, 0x80, 0x48, 0x7a, 0xa9, 0x45, 0xb9, 0xfb, 0x88, 0x26, 0x95, 0xd0, // +|...R..Hz.E...&..|
+ 		0xc5, 0x6d, 0xbd, 0xc7,                                                                         // +|.m..|
  	},
  	Dependencies:     {"merged-usrsbin", "wolfi-baselayout"},
  	Provides:         nil,
  	InstallIf:        nil,
- 	Size:             10840,
+ 	Size:             10897,
- 	InstalledSize:    40191,
+ 	InstalledSize:    40545,
  	ProviderPriority: 0,
- 	BuildTime:        s"2025-06-28 11:21:54 +0000 UTC",
+ 	BuildTime:        s"2025-07-10 08:30:07 +0000 UTC",
- 	BuildDate:        1751109714,
+ 	BuildDate:        1752136207,
  	RepoCommit: strings.Join({
- 		"f754445ff42a1bdaa045259910ef85075a165361",
+ 		"4f40198b061c61e0df0ff31c0abf9c5457fec52a",
  	}, ""),
  	Replaces: nil,
  	DataHash: "",
  }

➕ Added:

  • var/lib/db/sbom/flux-source-controller-bitnami-compat-1.6.2-r2.spdx.json

➖ Removed:

  • var/lib/db/sbom/flux-source-controller-bitnami-compat-1.6.2-r1.spdx.json

🔺 Changed:

.PKGINFO
- -rw-r--r-- 465 2025-06-28 11:21:54 .PKGINFO
+ -rw-r--r-- 465 2025-07-10 08:30:07 .PKGINFO
.melange.yaml
- -rw-r--r-- 47423 2025-06-28 11:21:54 .melange.yaml
+ -rw-r--r-- 47456 2025-07-10 08:30:07 .melange.yaml

x86_64/flux-source-controller-iamguarded-compat-1.6.2-r1.apk -> x86_64/flux-source-controller-iamguarded-compat-1.6.2-r2.apk

📦 Package diff:

  &apk.Package{
  	Name:        "flux-source-controller-iamguarded-compat",
- 	Version:     "1.6.2-r1",
+ 	Version:     "1.6.2-r2",
  	Arch:        "x86_64",
  	Description: "compat package for iamguarded",
  	... // 2 identical fields
  	Maintainer: "wolfi",
  	URL:        "",
  	Checksum: []uint8{
- 		0x1a, 0x9b, 0xfa, 0xa7, 0x83, 0xc9, 0x91, 0xde, 0x03, 0x63, 0xdb, 0x7a, 0xc8, 0x4a, 0x54, 0x7c, // -|.........c.z.JT||
- 		0x77, 0x9c, 0x08, 0xbf,                                                                         // -|w...|
+ 		0xfe, 0x43, 0xfe, 0xc4, 0x04, 0x9f, 0xf9, 0x0a, 0x12, 0x1e, 0x32, 0x8a, 0xfa, 0x23, 0xea, 0x5e, // +|.C........2..#.^|
+ 		0x41, 0xe3, 0x4c, 0x5c,                                                                         // +|A.L\|
  	},
  	Dependencies:     nil,
- 	Provides:         []string{"cmd:run-script=1.6.2-r1"},
+ 	Provides:         []string{"cmd:run-script=1.6.2-r2"},
  	InstallIf:        nil,
- 	Size:             11986,
+ 	Size:             12041,
- 	InstalledSize:    54127,
+ 	InstalledSize:    54481,
  	ProviderPriority: 0,
- 	BuildTime:        s"2025-06-28 11:21:54 +0000 UTC",
+ 	BuildTime:        s"2025-07-10 08:30:07 +0000 UTC",
- 	BuildDate:        1751109714,
+ 	BuildDate:        1752136207,
  	RepoCommit: strings.Join({
- 		"f754445ff42a1bdaa045259910ef85075a165361",
+ 		"4f40198b061c61e0df0ff31c0abf9c5457fec52a",
  	}, ""),
  	Replaces: nil,
  	DataHash: "",
  }

➕ Added:

  • var/lib/db/sbom/flux-source-controller-iamguarded-compat-1.6.2-r2.spdx.json

➖ Removed:

  • var/lib/db/sbom/flux-source-controller-iamguarded-compat-1.6.2-r1.spdx.json

🔺 Changed:

.PKGINFO
- -rw-r--r-- 422 2025-06-28 11:21:54 .PKGINFO
+ -rw-r--r-- 422 2025-07-10 08:30:07 .PKGINFO
.melange.yaml
- -rw-r--r-- 47423 2025-06-28 11:21:54 .melange.yaml
+ -rw-r--r-- 47456 2025-07-10 08:30:07 .melange.yaml
opt/iamguarded/LICENSE-Chainguard
- -rw-r--r-- 209 2025-06-28 11:21:54 LICENSE-Chainguard
+ -rw-r--r-- 209 2025-07-10 08:30:07 LICENSE-Chainguard
opt/iamguarded/NOTICE
- -rw-r--r-- 987 2025-06-28 11:21:54 NOTICE
+ -rw-r--r-- 987 2025-07-10 08:30:07 NOTICE
usr/bin/run-script
- -rwxr-xr-x 431 2025-06-28 11:21:54 run-script
+ -rwxr-xr-x 431 2025-07-10 08:30:07 run-script