Skip to content

gh/2.83.1-r2: cve remediation#75109

Merged
OddBloke merged 2 commits into
mainfrom
cve-gh-2.83.1-r2-c1efa1a4c43a745cd462d346a286e7d5
Dec 12, 2025
Merged

gh/2.83.1-r2: cve remediation#75109
OddBloke merged 2 commits into
mainfrom
cve-gh-2.83.1-r2-c1efa1a4c43a745cd462d346a286e7d5

gh: switch remediation bump to package pulling dep in recursively

1c6776b
Select commit
Loading
Failed to load commit list.
Chainguard Internal / elastic-build succeeded Dec 11, 2025 in 5m 14s

APKs built successfully

Build ID: b456f11d-ed6d-4814-984a-17f3f4bcf246

Details

builds

x86_64 Logs

Click to expand
ng krb5-libs (1.22.1-r1)
installing libtirpc (1.3.7-r1)
installing libpcre2-8-0 (10.47-r0)
installing libsepol (3.9-r1)
installing libselinux (3.9-r1)
installing libnftnl (1.3.1-r0)
installing xtables (1.8.11-r29)
installing libcap (2.77-r0)
installing iproute2 (6.17.0-r2)
installing libstdc++ (15.2.0-r6)
installing inih (62-r1)
installing liburcu (0.15.5-r0)
installing libblkid (2.41.2-r2)
installing libuuid (2.41.2-r2)
installing xfsprogs-core (6.17.0-r2)
installing xfsprogs (6.17.0-r2)
installing libmount (2.41.2-r2)
installing mount (2.41.2-r2)
installing ncurses-terminfo-base (6.5_p20251025-r1)
installing ncurses (6.5_p20251025-r1)
installing setarch (2.41.2-r2)
installing libfdisk (2.41.2-r2)
installing sqlite-libs (3.51.1-r0)
installing util-linux (2.41.2-r2)
installing libsmartcols (2.41.2-r2)
installing util-linux-misc (2.41.2-r2)
installing libxcrypt (4.5.2-r0)
installing libcrypt1 (2.42-r4)
installing linux-pam (1.7.1-r3)
installing openssh-keygen (10.2_p1-r2)
installing openssh-server-config (10.2_p1-r2)
installing openssh-server (10.2_p1-r2)
installing busybox (1.37.0-r50)
installing microvm-init (0.0.1-r15)
qemu: starting VM
qemu: waiting for SSH
conn read: read tcp 127.0.0.1:36932->127.0.0.1:34953: i/o timeout
qemu: meta-data=/dev/vda               isize=512    agcount=8, agsize=1638400 blks
qemu:          =                       sectsz=4096  attr=2, projid32bit=1
qemu:          =                       crc=1        finobt=1, sparse=1, rmapbt=1
qemu:          =                       reflink=1    bigtime=1 inobtcount=1 nrext64=1
qemu:          =                       exchange=0   metadir=0
qemu: data     =                       bsize=4096   blocks=13107200, imaxpct=25
qemu:          =                       sunit=0      swidth=0 blks
qemu: naming   =version 2              bsize=4096   ascii-ci=0, ftype=1, parent=0
qemu: log      =internal log           bsize=4096   blocks=16384, version=2
qemu:          =                       sectsz=4096  sunit=1 blks, lazy-count=1
qemu: realtime =none                   extsz=4096   blocks=0, rtextents=0
qemu:          =                       rgcount=0    rgsize=0 extents
qemu:          =                       zoned=0      start=0 reserved=0
qemu: Discarding blocks...Done.
qemu: [INIT] Checking for init.d scripts...
qemu: [INIT] No /opt/melange/init.d directory (optional, skipping)
qemu: ssh-keygen: generating new host keys: RSA ECDSA 
qemu: Server listening on 0.0.0.0 port 2223.
qemu: Server listening on 0.0.0.0 port 22.
conn read: read tcp 127.0.0.1:36948->127.0.0.1:34953: i/o timeout
qemu: VM started successfully, SSH server is up
qemu: Connection closed by 10.0.2.2 port 36952
qemu: verifying VM host key against pre-provisioned key
qemu: Accepted publickey for root from 10.0.2.2 port 36958 ssh2: ECDSA SHA256:N4x3RG+De4Sa7sbtr+EeXyVpxwtKYcgErz7PgbJbpbo
qemu: VM host key successfully verified against pre-provisioned key
qemu: Connection closed by 10.0.2.2 port 36958
qemu: Accepted publickey for root from 10.0.2.2 port 36972 ssh2: ECDSA SHA256:N4x3RG+De4Sa7sbtr+EeXyVpxwtKYcgErz7PgbJbpbo
qemu: Accepted publickey for root from 10.0.2.2 port 34462 ssh2: ECDSA SHA256:N4x3RG+De4Sa7sbtr+EeXyVpxwtKYcgErz7PgbJbpbo
qemu: Accepted publickey for root from 10.0.2.2 port 36978 ssh2: ECDSA SHA256:N4x3RG+De4Sa7sbtr+EeXyVpxwtKYcgErz7PgbJbpbo
qemu: running kernel version: 6.16.10-r2-qemu-generic #Chainguard SMP PREEMPT_DYNAMIC Fri Oct  3 22:31:32 UTC 2025
qemu: setting up local workspace
qemu: unmounting host workspace from guest
running the main test pipeline
gh version 2.83.1 (2025-12-11)
https://github.com/cli/cli/releases/tag/v2.83.1
Work seamlessly with GitHub from the command line.

USAGE
  gh <command> <subcommand> [flags]

CORE COMMANDS
  auth:          Authenticate gh and git with GitHub
  browse:        Open repositories, issues, pull requests, and more in the browser
  codespace:     Connect to and manage codespaces
  gist:          Manage gists
  issue:         Manage issues
  org:           Manage organizations
  pr:            Manage pull requests
  project:       Work with GitHub Projects.
  release:       Manage releases
  repo:          Manage repositories

GITHUB ACTIONS COMMANDS
  cache:         Manage GitHub Actions caches
  run:           View details about workflow runs
  workflow:      View details about GitHub Actions workflows

ALIAS COMMANDS
  co:            Alias for "pr checkout"

ADDITIONAL COMMANDS
  agent-task:    Work with agent tasks (preview)
  alias:         Create command shortcuts
  api:           Make an authenticated GitHub API request
  attestation:   Work with artifact attestations
  completion:    Generate shell completion scripts
  config:        Manage configuration for gh
  extension:     Manage gh extensions
  gpg-key:       Manage GPG keys
  label:         Manage labels
  preview:       Execute previews for gh features
  ruleset:       View info about repo rulesets
  search:        Search for repositories, issues, and pull requests
  secret:        Manage GitHub secrets
  ssh-key:       Manage SSH keys
  status:        Print information about relevant issues, pull requests, and notifications across repositories
  variable:      Manage GitHub Actions variables

HELP TOPICS
  accessibility: Learn about GitHub CLI's accessibility experiences
  actions:       Learn about working with GitHub Actions
  environment:   Environment variables that can be used with gh
  exit-codes:    Exit codes used by gh
  formatting:    Formatting options for JSON data exported from gh
  mintty:        Information about using gh with MinTTY
  reference:     A comprehensive reference of all gh commands

FLAGS
  --help      Show help for command
  --version   Show gh version

EXAMPLES
  $ gh issue create
  $ gh repo clone cli/cli
  $ gh pr checkout 321

LEARN MORE
  Use `gh <command> <subcommand> --help` for more information about a command.
  Read the manual at https://cli.github.com/manual
  Learn about exit codes using `gh help exit-codes`
  Learn about accessibility experiences using `gh help accessibility`

qemu: sending shutdown signal
running test pipeline for subpackage gh-doc
melange v0.36.0 with runner qemu is testing:
image configuration:
  contents:
    build repositories: []
    runtime repositories: []
    repositories: []
    keyring:      []
    packages:     [apk-tools gh-doc grep man-db texinfo]
  accounts:
    runas:  
    users:
      - uid=1000(build) gid=1000
    groups:
      - gid=1000(build) members=[build]
installing wolfi-baselayout (20230201-r24)
installing ca-certificates-bundle (20251003-r0)
installing ld-linux (2.42-r4)
installing libgcc (15.2.0-r6)
installing glibc-locale-posix (2.42-r4)
installing glibc (2.42-r4)
installing zlib (1.3.1-r51)
installing libcrypto3 (3.6.0-r6)
installing libssl3 (3.6.0-r6)
installing apk-tools (2.14.10-r9)
installing libpipeline (1.5.8-r2)
installing libseccomp (2.6.0-r1)
installing libstdc++ (15.2.0-r6)
installing groff-base (1.23.0-r7)
installing libbz2-1 (1.0.8-r21)
installing libxcrypt (4.5.2-r0)
installing libcrypt1 (2.42-r4)
installing perl (5.42.0-r1)
installing groff (1.23.0-r7)
installing gdbm (1.26-r1)
installing man-db (2.13.1-r51)
installing gh-doc (2.83.1-r3)
installing libpcre2-8-0 (10.47-r0)
installing grep (3.12-r3)
installing ncurses-terminfo-base (6.5_p20251025-r1)
installing ncurses (6.5_p20251025-r1)
installing texinfo (7.2-r4)
installing wolfi-keys (1-r12)
installing busybox (1.37.0-r50)
installing wolfi-base (1-r7)
qemu: generating ssh key pairs for ephemeral VM
qemu: generating SSH host key for VM
qemu: starting VM
qemu: waiting for SSH
conn read: read tcp 127.0.0.1:49214->127.0.0.1:40115: i/o timeout
qemu: meta-data=/dev/vda               isize=512    agcount=8, agsize=1638400 blks
qemu:          =                       sectsz=4096  attr=2, projid32bit=1
qemu:          =                       crc=1        finobt=1, sparse=1, rmapbt=1
qemu:          =                       reflink=1    bigtime=1 inobtcount=1 nrext64=1
qemu:          =                       exchange=0   metadir=0
qemu: data     =                       bsize=4096   blocks=13107200, imaxpct=25
qemu:          =                       sunit=0      swidth=0 blks
qemu: naming   =version 2              bsize=4096   ascii-ci=0, ftype=1, parent=0
qemu: log      =internal log           bsize=4096   blocks=16384, version=2
qemu:          =                       sectsz=4096  sunit=1 blks, lazy-count=1
qemu: realtime =none                   extsz=4096   blocks=0, rtextents=0
qemu:          =                       rgcount=0    rgsize=0 extents
qemu:          =                       zoned=0      start=0 reserved=0
qemu: Discarding blocks...Done.
qemu: [INIT] Checking for init.d scripts...
qemu: [INIT] No /opt/melange/init.d directory (optional, skipping)
qemu: ssh-keygen: generating new host keys: RSA ECDSA 
qemu: Server listening on 0.0.0.0 port 2223.
qemu: Server listening on 0.0.0.0 port 22.
conn read: read tcp 127.0.0.1:56702->127.0.0.1:40115: i/o timeout
qemu: VM started successfully, SSH server is up
qemu: Connection closed by 10.0.2.2 port 56714
qemu: verifying VM host key against pre-provisioned key
qemu: Accepted publickey for root from 10.0.2.2 port 56724 ssh2: ECDSA SHA256:SoC09OMLzCgxZfNLlermUf7SiKnZAmQPCKUqDQjnroc
qemu: VM host key successfully verified against pre-provisioned key
qemu: Connection closed by 10.0.2.2 port 56724
qemu: Accepted publickey for root from 10.0.2.2 port 56726 ssh2: ECDSA SHA256:SoC09OMLzCgxZfNLlermUf7SiKnZAmQPCKUqDQjnroc
qemu: Accepted publickey for root from 10.0.2.2 port 51304 ssh2: ECDSA SHA256:SoC09OMLzCgxZfNLlermUf7SiKnZAmQPCKUqDQjnroc
qemu: Accepted publickey for root from 10.0.2.2 port 56736 ssh2: ECDSA SHA256:SoC09OMLzCgxZfNLlermUf7SiKnZAmQPCKUqDQjnroc
qemu: running kernel version: 6.16.10-r2-qemu-generic #Chainguard SMP PREEMPT_DYNAMIC Fri Oct  3 22:31:32 UTC 2025
qemu: setting up local workspace
qemu: unmounting host workspace from guest
running step "test/docs"
running step "docs readability check"
troff:<standard input>:54: warning [p 1, 9.5i]: cannot adjust line
troff:<standard input>:42: warning [p 1, 6.7i]: cannot adjust line
troff:<standard input>:37: warning [p 1, 6.5i]: cannot adjust line

aarch64 Logs

Click to expand
ackages.tar sha256sum: ed4b971cf6212188456049f270af18313e57b8638958c914bb9e37100e2a0b52
sha256sum "ed4b971cf6212188456049f270af18313e57b8638958c914bb9e37100e2a0b52" written to /dev/termination-log
Built 2 packages, hash: ed4b971cf6212188456049f270af18313e57b8638958c914bb9e37100e2a0b52, size: 13629952 bytes
uploading final packages tarball...
running command curl [-s --upload-file packages.tar -H Content-Type: application/octet-stream https://storage.googleapis.com/prod-bundle-staging/wolfi/aarch64/1765487252813293713-gh-2.83.1-r3.tar.gz?Expires=1765530452&GoogleAccessId=ebuild-zasv64d5x1oc4m3epw39yod%40prod-enforce-fabc.iam.gserviceaccount.com&Signature=cx2vHueE4F2m7IQXRUtsfz%2FC1PbFt1i%2BTF6BKQNVsdzmnNWROhk3CxZMGAv7T3KVKYKaHVzInjKF6%2Bc1GIXa8xZ9GgwHQ%2BnumhLynHW5mPC8464OQBK4d%2F1iUV03CA4SShFIm6IVV1UNgR3IdUFThDiHeDS1VUFpKV5lg8tEMXjyNQ%2BkAaQRFusR53abh5%2F6%2B114ZvwNydvZqXVl%2FZkErO8p8gvgA34CmG4QeA8WY%2FkMYNiHXfy1nl05G%2BNHgQf%2Fi7z8V4vHYzRlWlyc1I7J1thkHx83VVB91gGcuncA%2FAMZBsnOUFh%2FZe0cLRfy0uDTSpRcXg0UroDISt7GihC%2F7g%3D%3D]
command "curl" completed successfully
upload completed successfully
parsed env
configuring puller identity "720909c9f5279097d847ad02a2f24ba8f59de36a/a49c7fedc33adf69"...
running command chainctl [auth login --audience apk.cgr.dev --identity 720909c9f5279097d847ad02a2f24ba8f59de36a/a49c7fedc33adf69]
Successfully exchanged token.
Valid! Id: 720909c9f5279097d847ad02a2f24ba8f59de36a/a49c7fedc33adf69
Updates are available for chainctl (current version: 0.2.183; latest: 0.2.184). To install, please run:
    $ chainctl update
command "chainctl" completed successfully
puller identity configured successfully
puller identity configured successfully
running tests...
running command /usr/bin/dind [dockerd] in background
command "/usr/bin/dind" started successfully
running command bash [-c 
  # Retry up to 60 seconds to wait for docker to start.
  worked=false
  for i in $(seq 60); do
    if docker info >/dev/null 2>&1; then
	  worked=true
	  break
    fi
    echo "docker healthcheck failed, docker is not ready, retrying... ($i/60 seconds so far)..."
    sleep 1
  done

  if [ "$worked" = "false" ]; then
    echo "Failed to start docker after 60 seconds"
    exit 1
  fi
]
command "bash" completed successfully
running command melange [test gh.yaml --gcplog --source-dir gh --test-package-append wolfi-base --arch=aarch64 --env-file=build-aarch64.env --pipeline-dirs=./pipelines --runner=docker --repository-append=https://apk.cgr.dev/chainguard --repository-append=https://apk.cgr.dev/wolfi-presubmit/97c060e33155d5d222059eb4dddd86eaecd18c83 --repository-append=https://apk.cgr.dev/wolfi-presubmit/97c060e33155d5d222059eb4dddd86eaecd18c83]
melange v0.36.0 with runner docker is testing:
image configuration:
  contents:
    build repositories: []
    runtime repositories: []
    repositories: []
    keyring:      []
    packages:     [gh]
  accounts:
    runas:  
    users:
      - uid=1000(build) gid=1000
    groups:
      - gid=1000(build) members=[build]
installing gh (2.83.1-r3)
installing wolfi-keys (1-r12)
installing wolfi-baselayout (20230201-r24)
installing ca-certificates-bundle (20251003-r0)
installing libgcc (15.2.0-r6)
installing glibc-locale-posix (2.42-r4)
installing glibc (2.42-r4)
installing ld-linux (2.42-r4)
installing zlib (1.3.1-r51)
installing libcrypto3 (3.6.0-r6)
installing libssl3 (3.6.0-r6)
installing apk-tools (2.14.10-r9)
installing libxcrypt (4.5.2-r0)
installing libcrypt1 (2.42-r4)
installing busybox (1.37.0-r50)
installing wolfi-base (1-r7)
layer digest: sha256:249b182b7f73df2dec3345da1993cc18a035cd98b784b626d8b245d947373bf9
layer diffID: sha256:3f8459daceb23590472258a63721590e81894ad6c291c9b90d943f5246e55f2d
saving OCI image locally: apko.local/cache:11e6aef7978d7161378c798b50b59bed282639a9024783aaa8e38c8938963266
tagging local image apko.local/cache:11e6aef7978d7161378c798b50b59bed282639a9024783aaa8e38c8938963266 as index.docker.io/library/melange:latest
populating workspace /tmp/melange-workspace-3471088607 from gh
running the main test pipeline
gh version 2.83.1 (2025-12-11)
https://github.com/cli/cli/releases/tag/v2.83.1
Work seamlessly with GitHub from the command line.

USAGE
  gh <command> <subcommand> [flags]

CORE COMMANDS
  auth:          Authenticate gh and git with GitHub
  browse:        Open repositories, issues, pull requests, and more in the browser
  codespace:     Connect to and manage codespaces
  gist:          Manage gists
  issue:         Manage issues
  org:           Manage organizations
  pr:            Manage pull requests
  project:       Work with GitHub Projects.
  release:       Manage releases
  repo:          Manage repositories

GITHUB ACTIONS COMMANDS
  cache:         Manage GitHub Actions caches
  run:           View details about workflow runs
  workflow:      View details about GitHub Actions workflows

ALIAS COMMANDS
  co:            Alias for "pr checkout"

ADDITIONAL COMMANDS
  agent-task:    Work with agent tasks (preview)
  alias:         Create command shortcuts
  api:           Make an authenticated GitHub API request
  attestation:   Work with artifact attestations
  completion:    Generate shell completion scripts
  config:        Manage configuration for gh
  extension:     Manage gh extensions
  gpg-key:       Manage GPG keys
  label:         Manage labels
  preview:       Execute previews for gh features
  ruleset:       View info about repo rulesets
  search:        Search for repositories, issues, and pull requests
  secret:        Manage GitHub secrets
  ssh-key:       Manage SSH keys
  status:        Print information about relevant issues, pull requests, and notifications across repositories
  variable:      Manage GitHub Actions variables

HELP TOPICS
  accessibility: Learn about GitHub CLI's accessibility experiences
  actions:       Learn about working with GitHub Actions
  environment:   Environment variables that can be used with gh
  exit-codes:    Exit codes used by gh
  formatting:    Formatting options for JSON data exported from gh
  mintty:        Information about using gh with MinTTY
  reference:     A comprehensive reference of all gh commands

FLAGS
  --help      Show help for command
  --version   Show gh version

EXAMPLES
  $ gh issue create
  $ gh repo clone cli/cli
  $ gh pr checkout 321

LEARN MORE
  Use `gh <command> <subcommand> --help` for more information about a command.
  Read the manual at https://cli.github.com/manual
  Learn about exit codes using `gh help exit-codes`
  Learn about accessibility experiences using `gh help accessibility`

pod b6434557a6517e4fb7f8a914c0616e2bc911b34b6a9d75902a384e9a1538f290 terminated
running test pipeline for subpackage gh-doc
melange v0.36.0 with runner docker is testing:
image configuration:
  contents:
    build repositories: []
    runtime repositories: []
    repositories: []
    keyring:      []
    packages:     [apk-tools gh-doc grep man-db texinfo]
  accounts:
    runas:  
    users:
      - uid=1000(build) gid=1000
    groups:
      - gid=1000(build) members=[build]
installing wolfi-baselayout (20230201-r24)
installing ca-certificates-bundle (20251003-r0)
installing libgcc (15.2.0-r6)
installing glibc-locale-posix (2.42-r4)
installing glibc (2.42-r4)
installing ld-linux (2.42-r4)
installing zlib (1.3.1-r51)
installing libcrypto3 (3.6.0-r6)
installing libssl3 (3.6.0-r6)
installing apk-tools (2.14.10-r9)
installing libpipeline (1.5.8-r2)
installing libseccomp (2.6.0-r1)
installing libstdc++ (15.2.0-r6)
installing groff-base (1.23.0-r7)
installing libbz2-1 (1.0.8-r21)
installing libxcrypt (4.5.2-r0)
installing libcrypt1 (2.42-r4)
installing perl (5.42.0-r1)
installing groff (1.23.0-r7)
installing gdbm (1.26-r1)
installing man-db (2.13.1-r51)
installing gh-doc (2.83.1-r3)
installing libpcre2-8-0 (10.47-r0)
installing grep (3.12-r3)
installing ncurses-terminfo-base (6.5_p20251025-r1)
installing ncurses (6.5_p20251025-r1)
installing texinfo (7.2-r4)
installing wolfi-keys (1-r12)
installing busybox (1.37.0-r50)
installing wolfi-base (1-r7)
layer digest: sha256:a80c60f290e99d88f8c26e43d2ba5c153b4d8d38fc4407ec7b721eea981705cb
layer diffID: sha256:49c4a0f1ad2c45c83916754a691012e4e14ab0bcc684a71349e12b3fc421660b
saving OCI image locally: apko.local/cache:e0418a3303599b874e10ebea387fcea51eb6a484877f294801e4418e582d3245
tagging local image apko.local/cache:e0418a3303599b874e10ebea387fcea51eb6a484877f294801e4418e582d3245 as index.docker.io/library/melange:latest
running step "test/docs"
running step "docs readability check"
troff:<standard input>:54: warning [p 1, 9.5i]: cannot adjust line
troff:<standard input>:42: warning [p 1, 6.7i]: cannot adjust line
troff:<standard input>:37: warning [p 1, 6.5i]: cannot adjust line
troff:<standard input>:22: warning: special character 'OK' not defined
troff:<standard input>:18: warning [p 1, 3.2i]: cannot adjust line
troff:<standard input>:24: warning [p 1, 4.5i]: cannot adjust line
troff:<standard input>:18: warning [p 1, 3.2i]: cannot adjust line
troff:<standard input>:24: warning [p 1, 4.5i]: cannot adjust line
troff:<standard input>:20: warning [p 1, 3.5i]: cannot adjust line
troff:<standard input>:43: warning [p 1, 7.8i]: cannot adjust line
troff:<standard input>:43: warning [p 1, 8.0i]: cannot adjust line
troff:<standard input>:61: warning [p 1, 10.8i]: cannot adjust line
troff:<standard input>:18: warning [p 1, 3.0i]: cannot adjust line
troff:<standard input>:22: warning [p 1, 3.8i]: cannot adjust line
troff:<standard input>:28: warning [p 1, 5.2i]: cannot adjust line
troff:<standard input>:153: warning [p 3, 3.8i]: cannot adjust line
troff:<standard input>:28: warning [p 1, 5.2i]: cannot adjust line
troff:<standard input>:185: warning [p 3, 9.3i]: cannot adjust line
troff:<standard input>:22: warning [p 1, 3.8i]: cannot adjust line
troff:<standard input>:44: warning [p 1, 7.7i]: cannot adjust line
troff:<standard input>:44: warning [p 1, 7.8i]: cannot adjust line
troff:<standard input>:46: warning [p 1, 8.2i]: cannot adjust line
troff:<standard input>:46: warning [p 1, 8.3i]: cannot adjust line
pod 27f28c8cb3110e7f190e3e784df6fa4d36399136a957371e55aac8915a07c0c7 terminated
command "melange" completed successfully
tests completed successfully
all tests passed

Indexes

https://apk.cgr.dev/wolfi-presubmit/97c060e33155d5d222059eb4dddd86eaecd18c83

Packages

Tests

More Observability

Command

cg build log \
  --build-id b456f11d-ed6d-4814-984a-17f3f4bcf246 \
  --project prod-wolfi-os \
  --cluster elastic-pre-a \
  --namespace pre-wolfi \
  --start 2025-12-11T21:04:10Z \
  --end 2025-12-11T21:19:25Z