Skip to content

Remove unused bump

cc8e93b
Select commit
Loading
Failed to load commit list.
Merged

verticadb-operator/25.4.0.0-r1: cve remediation #76231

Remove unused bump
cc8e93b
Select commit
Loading
Failed to load commit list.
Chainguard Internal / elastic-build succeeded Dec 18, 2025 in 3m 42s

APKs built successfully

Build ID: 6efdb6a6-26fe-4767-b33e-d82676be5732

Details

builds

x86_64 Logs

Click to expand
8s.io/utils v0.0.0-20230726121419-3b25d923346b
go: downloading k8s.io/klog/v2 v2.120.1
go: downloading golang.org/x/net v0.24.0
go: downloading github.com/go-logr/logr v1.4.1
go: downloading golang.org/x/text v0.14.0
go: downloading golang.org/x/mod v0.17.0
go: downloading golang.org/x/sync v0.7.0
go generate ./...
/home/build/bin/controller-gen rbac:roleName=manager-role crd paths="./..." output:crd:artifacts:config=config/crd/bases
/home/build/bin/controller-gen object:headerFile="hack/boilerplate.go.txt" paths="./..."
go fmt ./...
go vet ./...
running step "go/build"
running pipeline for subpackage verticadb-operator-compat
retrieving workspace from builder: 
fetching remote workspace
retrieved and wrote post-build workspace to: /tmp/melange-workspace-1979115382
running package linters for verticadb-operator
linting apk: verticadb-operator
no lint findings to persist for package verticadb-operator
running package linters for verticadb-operator-compat
linting apk: verticadb-operator-compat
no lint findings to persist for package verticadb-operator-compat
checking license information
  LICENSE: Apache-2.0 (0.996178) (notice)
  local-libs/vcluster/LICENSE: Apache-2.0 (0.996178) (notice)
  workspace-verticadb-operator/local-libs/vcluster/LICENSE: Apache-2.0 (0.996178) (notice)
checking gathered license information against the configuration
no license differences detected
license information check complete
generating enhanced Syft SBOMs merged with melange metadata
invalid license: NOASSERTION
invalid license: NOASSERTION
created base melange SBOMs with build metadata
scanning package directory with Syft to enhance SBOM
generating SBOM from unpacked directory
finished Syft SBOM generation
successfully merged Syft scan results with melange SBOM
scanning package directory with Syft to enhance SBOM
generating SBOM from unpacked directory
finished Syft SBOM generation
successfully merged Syft scan results with melange SBOM
enhanced all SBOMs with Syft scan results
generating package verticadb-operator-25.4.0.0-r2
scanning for ld.so.conf.d files...
2025/12/18 14:15:13 INFO completed enhanced Syft SBOM generation with merged metadata
scanning for shared object dependencies...
scanning for commands...
  found command usr/bin/manager
scanning for -doc package...
scanning for pkg-config data...
scanning for python modules...
scanning for ruby gems...
scanning for shbang deps...
scanning for kernel dependencies...
  provides:
    cmd:manager=25.4.0.0-r2
  installed-size: 79159939
  data.tar.gz digest: 95e9641dfd9bc035e608068d05106930a373864422c5ce492f08924a00f752cd
wrote packages/x86_64/verticadb-operator-25.4.0.0-r2.apk
generating package verticadb-operator-compat-25.4.0.0-r2
scanning for ld.so.conf.d files...
scanning for shared object dependencies...
scanning for commands...
scanning for -doc package...
scanning for pkg-config data...
scanning for python modules...
scanning for ruby gems...
scanning for shbang deps...
scanning for kernel dependencies...
  installed-size: 28150
  data.tar.gz digest: d8c7c8f57839869049a877a78c943ec070a9a95ac0f619299472b54beeb033e8
wrote packages/x86_64/verticadb-operator-compat-25.4.0.0-r2.apk
cleaning Workspace by removing 41 file/directories in /home/build
generating apk index from packages in packages/x86_64
processing package packages/x86_64/verticadb-operator-compat-25.4.0.0-r2.apk
processing package packages/x86_64/verticadb-operator-25.4.0.0-r2.apk
updating index at packages/x86_64/APKINDEX.tar.gz with new packages: [verticadb-operator-25.4.0.0-r2 verticadb-operator-compat-25.4.0.0-r2]
qemu: sending shutdown signal
build completed successfully
running malcontent scan...
found 2 APK files to scan
scanning packages/x86_64/verticadb-operator-25.4.0.0-r2.apk -> packages/verticadb-operator-25.4.0.0-r2/mal-scan.json
running command mal [--format=json --exit-extraction=false --min-risk=critical --min-file-risk=critical --quantity-increases-risk=true --output=packages/verticadb-operator-25.4.0.0-r2/mal-scan.json scan packages/x86_64/verticadb-operator-25.4.0.0-r2.apk]
command "mal" completed successfully
scanning packages/x86_64/verticadb-operator-compat-25.4.0.0-r2.apk -> packages/verticadb-operator-compat-25.4.0.0-r2/mal-scan.json
running command mal [--format=json --exit-extraction=false --min-risk=critical --min-file-risk=critical --quantity-increases-risk=true --output=packages/verticadb-operator-compat-25.4.0.0-r2/mal-scan.json scan packages/x86_64/verticadb-operator-compat-25.4.0.0-r2.apk]
command "mal" completed successfully
malcontent scan completed successfully for 2 APKs in 13s
creating packages tarball...
running command tar [-C packages -cf packages.tar .]
command "tar" completed successfully
packages.tar sha256sum: 0dd5a270b172580e16821de9ab58652040f2eaaa5995cc7c7c8d6c2098298187
sha256sum "0dd5a270b172580e16821de9ab58652040f2eaaa5995cc7c7c8d6c2098298187" written to /dev/termination-log
Built 2 packages, hash: 0dd5a270b172580e16821de9ab58652040f2eaaa5995cc7c7c8d6c2098298187, size: 23463936 bytes
uploading final packages tarball...
running command curl [-s --upload-file packages.tar -H Content-Type: application/octet-stream https://storage.googleapis.com/prod-bundle-staging/wolfi/x86_64/1766067248423190536-verticadb-operator-25.4.0.0-r2.tar.gz?Expires=1766110448&GoogleAccessId=ebuild-zasv64d5x1oc4m3epw39yod%40prod-enforce-fabc.iam.gserviceaccount.com&Signature=mOgduOSxMpBDvOS1MLedQToCFItnnBhkrPgGKg3RzfE4QJfLufdBWc4KI6J6sY3QOJHV9701I35hlzG4ZVNOk415mRIn4GvmpS%2Br%2BsS0wqc0K6PmdKQLspQKUdHF72MrDdfllUURGqtnQsTEIc%2F1%2F39VVOJIXI1O1eMnweFgpwtE6nXF3MknMr3WXLhcJzT%2F%2BCwjNmjSanyPW1%2BABOcsWe5oso06dwx2dVN9ItS4mSEIZN%2Fg5EQpw%2FWYwc5vrx5QkJB%2BzUBgEUOGIyBBaCYsqSievizgsD64GR596hn1rrEYqZlmJAZU%2BzKMYg4YJ9d4CyDStgBb%2FlCIhvrnf5j58Q%3D%3D]
command "curl" completed successfully
upload completed successfully
parsed env
using enhanced syft sbom melange runner
configuring puller identity "720909c9f5279097d847ad02a2f24ba8f59de36a/a49c7fedc33adf69"...
running command chainctl [auth login --audience apk.cgr.dev --identity 720909c9f5279097d847ad02a2f24ba8f59de36a/a49c7fedc33adf69]
Successfully exchanged token.
Valid! Id: 720909c9f5279097d847ad02a2f24ba8f59de36a/a49c7fedc33adf69
Updates are available for chainctl (current version: 0.2.185; latest: 0.2.186). To install, please run:
    $ chainctl update
command "chainctl" completed successfully
puller identity configured successfully
puller identity configured successfully
running tests...
running command /usr/bin/dind [dockerd] in background
command "/usr/bin/dind" started successfully
running command bash [-c 
  # Retry up to 60 seconds to wait for docker to start.
  worked=false
  for i in $(seq 60); do
    if docker info >/dev/null 2>&1; then
	  worked=true
	  break
    fi
    echo "docker healthcheck failed, docker is not ready, retrying... ($i/60 seconds so far)..."
    sleep 1
  done

  if [ "$worked" = "false" ]; then
    echo "Failed to start docker after 60 seconds"
    exit 1
  fi
]
command "bash" completed successfully
melange devel with runner qemu is testing:
image configuration:
  contents:
    build repositories: []
    runtime repositories: []
    repositories: []
    keyring:      []
    packages:     [verticadb-operator]
  accounts:
    runas:  
    users:
      - uid=1000(build) gid=1000
    groups:
      - gid=1000(build) members=[build]
installing verticadb-operator (25.4.0.0-r2)
installing wolfi-keys (1-r12)
installing wolfi-baselayout (20230201-r24)
installing ca-certificates-bundle (20251003-r0)
installing ld-linux (2.42-r4)
installing libgcc (15.2.0-r6)
installing glibc-locale-posix (2.42-r4)
installing glibc (2.42-r4)
installing zlib (1.3.1-r51)
installing libcrypto3 (3.6.0-r6)
installing libssl3 (3.6.0-r6)
installing apk-tools (2.14.10-r9)
installing libxcrypt (4.5.2-r0)
installing libcrypt1 (2.42-r4)
installing busybox (1.37.0-r50)
installing wolfi-base (1-r7)
populating workspace /tmp/melange-workspace-2553347613 from verticadb-operator
qemu: generating ssh key pairs for ephemeral VM
qemu: generating SSH host key for VM
qemu: generating base initramfs
image configuration:
  contents:
    build repositories: [https://apk.cgr.dev/chainguard]
    runtime repositories: []
    repositories: []
    keyring:      []
    packages:     [microvm-init]
installing wolfi-baselayout (20230201-r24)
installing ca-certificates-bundle (20251003-r0)
installing libgcc (15.2.0-r6)
installing glibc-locale-posix (2.42-r4)
installing glibc (2.42-r4)
installing ld-linux (2.42-r4)
installing gnutar-rmt (1.35-r6)
installing gnutar (1.35-r6)
installing libattr1 (2.5.2-r54)
installing attr (2.5.2-r54)
installing zlib (1.3.1-r51)
installing libzstd1 (1.5.7-r5)
installing xz (5.8.2-r0)
installing libcrypto3 (3.6.0-r6)
installing kmod (34.2-r42)
installing libmnl (1.0.5-r6)
installing libbz2-1 (1.0.8-r21)
installing libelf (0.194-r0)
installing libbpf (1.6.2-r0)
installing libverto (0.3.2-r6)
installing krb5-conf (1.0-r7)
installing libcom_err (1.47.3-r1)
installing keyutils-libs (1.6.3-r37)
installing libssl3 (3.6.0-r6)
installing krb5-libs (1.22.1-r1)
installing libtirpc (1.3.7-r1)
installing libpcre2-8-0 (10.47-r0)
installing libsepol (3.9-r1)
installing libselinux (3.9-r1)
installing libnftnl (1.3.1-r0)
installing xtables (1.8.11-r29)
installing libcap (2.77-r0)
installing iproute2 (6.17.0-r2)
installing libstdc++ (15.2.0-r6)
installing inih (62-r1)
installing liburcu (0.15.5-r0)
installing libblkid (2.41.3-r0)
installing libuuid (2.41.3-r0)
installing xfsprogs-core (6.17.0-r2)
installing xfsprogs (6.17.0-r2)
installing libmount (2.41.3-r0)
installing mount (2.41.3-r0)
installing libxcrypt (4.5.2-r0)
installing libcrypt1 (2.42-r4)
installing linux-pam (1.7.1-r3)
installing openssh-keygen (10.2_p1-r2)
installing openssh-server-config (10.2_p1-r2)
installing openssh-server (10.2_p1-r2)
installing ncurses-terminfo-base (6.5_p20251025-r1)
installing ncurses (6.5_p20251025-r1)
installing setarch (2.41.3-r0)
installing libfdisk (2.41.3-r0)
installing sqlite-libs (3.51.1-r0)
installing util-linux (2.41.3-r0)
installing libsmartcols (2.41.3-r0)
installing util-linux-misc (2.41.3-r0)
installing busybox (1.37.0-r50)
installing microvm-init (0.0.1-r15)
qemu: starting VM
qemu: waiting for SSH

aarch64 Logs

Click to expand
1
go: downloading golang.org/x/net v0.24.0
go: downloading github.com/go-logr/logr v1.4.1
go: downloading golang.org/x/text v0.14.0
go: downloading golang.org/x/sync v0.7.0
go: downloading golang.org/x/mod v0.17.0
go generate ./...
/home/build/bin/controller-gen rbac:roleName=manager-role crd paths="./..." output:crd:artifacts:config=config/crd/bases
/home/build/bin/controller-gen object:headerFile="hack/boilerplate.go.txt" paths="./..."
go fmt ./...
go vet ./...
running step "go/build"
running pipeline for subpackage verticadb-operator-compat
retrieving workspace from builder: 
retrieved and wrote post-build workspace to: /tmp/melange-workspace-4062803284
running package linters for verticadb-operator
linting apk: verticadb-operator
no lint findings to persist for package verticadb-operator
running package linters for verticadb-operator-compat
linting apk: verticadb-operator-compat
no lint findings to persist for package verticadb-operator-compat
checking license information
  LICENSE: Apache-2.0 (0.996178) (notice)
  local-libs/vcluster/LICENSE: Apache-2.0 (0.996178) (notice)
  workspace-verticadb-operator/local-libs/vcluster/LICENSE: Apache-2.0 (0.996178) (notice)
checking gathered license information against the configuration
no license differences detected
license information check complete
generating enhanced Syft SBOMs merged with melange metadata
invalid license: NOASSERTION
invalid license: NOASSERTION
created base melange SBOMs with build metadata
scanning package directory with Syft to enhance SBOM
generating SBOM from unpacked directory
finished Syft SBOM generation
successfully merged Syft scan results with melange SBOM
scanning package directory with Syft to enhance SBOM
generating SBOM from unpacked directory
finished Syft SBOM generation
successfully merged Syft scan results with melange SBOM
enhanced all SBOMs with Syft scan results
generating package verticadb-operator-25.4.0.0-r2
2025/12/18 14:14:55 INFO completed enhanced Syft SBOM generation with merged metadata
scanning for ld.so.conf.d files...
scanning for shared object dependencies...
scanning for commands...
  found command usr/bin/manager
scanning for -doc package...
scanning for pkg-config data...
scanning for python modules...
scanning for ruby gems...
scanning for shbang deps...
scanning for kernel dependencies...
  provides:
    cmd:manager=25.4.0.0-r2
  installed-size: 76237598
  data.tar.gz digest: b27267cf7281927b2a9430e7473931779b3cf79324a4b539892b3c8dc7e071d7
wrote packages/aarch64/verticadb-operator-25.4.0.0-r2.apk
generating package verticadb-operator-compat-25.4.0.0-r2
scanning for ld.so.conf.d files...
scanning for shared object dependencies...
scanning for commands...
scanning for -doc package...
scanning for pkg-config data...
scanning for python modules...
scanning for ruby gems...
scanning for shbang deps...
scanning for kernel dependencies...
  installed-size: 28152
  data.tar.gz digest: 1952045bc803e6d1710f5e4f05b0af3d3e6161f9381be91b3e9a066d523ff8ea
wrote packages/aarch64/verticadb-operator-compat-25.4.0.0-r2.apk
cleaning Workspace by removing 42 file/directories in /home/build
generating apk index from packages in packages/aarch64
processing package packages/aarch64/verticadb-operator-compat-25.4.0.0-r2.apk
processing package packages/aarch64/verticadb-operator-25.4.0.0-r2.apk
updating index at packages/aarch64/APKINDEX.tar.gz with new packages: [verticadb-operator-25.4.0.0-r2 verticadb-operator-compat-25.4.0.0-r2]
build completed successfully
running malcontent scan...
found 2 APK files to scan
scanning packages/aarch64/verticadb-operator-25.4.0.0-r2.apk -> packages/verticadb-operator-25.4.0.0-r2/mal-scan.json
running command mal [--format=json --exit-extraction=false --min-risk=critical --min-file-risk=critical --quantity-increases-risk=true --output=packages/verticadb-operator-25.4.0.0-r2/mal-scan.json scan packages/aarch64/verticadb-operator-25.4.0.0-r2.apk]
command "mal" completed successfully
scanning packages/aarch64/verticadb-operator-compat-25.4.0.0-r2.apk -> packages/verticadb-operator-compat-25.4.0.0-r2/mal-scan.json
running command mal [--format=json --exit-extraction=false --min-risk=critical --min-file-risk=critical --quantity-increases-risk=true --output=packages/verticadb-operator-compat-25.4.0.0-r2/mal-scan.json scan packages/aarch64/verticadb-operator-compat-25.4.0.0-r2.apk]
command "mal" completed successfully
malcontent scan completed successfully for 2 APKs in 9s
creating packages tarball...
running command tar [-C packages -cf packages.tar .]
command "tar" completed successfully
packages.tar sha256sum: 38dae3b1d719c2d3b1736253edf285d51674612eccf48da083cbfb3e0480b0c1
sha256sum "38dae3b1d719c2d3b1736253edf285d51674612eccf48da083cbfb3e0480b0c1" written to /dev/termination-log
Built 2 packages, hash: 38dae3b1d719c2d3b1736253edf285d51674612eccf48da083cbfb3e0480b0c1, size: 21203456 bytes
uploading final packages tarball...
running command curl [-s --upload-file packages.tar -H Content-Type: application/octet-stream https://storage.googleapis.com/prod-bundle-staging/wolfi/aarch64/1766067248423162305-verticadb-operator-25.4.0.0-r2.tar.gz?Expires=1766110448&GoogleAccessId=ebuild-zasv64d5x1oc4m3epw39yod%40prod-enforce-fabc.iam.gserviceaccount.com&Signature=QOhRfTkLMgkgdrlKQ6zwOi8BnthSsNYB2FQ4QNT0zUdtU0Gln5n09uAixxcOLQO%2B3W2nFRD66BCFg9h9YlNI77ycphw90kD5k1%2BILQZDKVX%2FNgNVHmjmkGpuyjCdYp%2BGEjqfd63jFuqc%2BliIIoPXAxITzDTM4XjML%2BIlbQVUf2DisUtVWmZXvYmCCjhP6aNp5osm%2B7Rwv7CTP7gDErLtmMSIPUXC97SlPiW8FgYCUvqrF8XEIkXHesqFWgCk8roZBeLp0U5TqBfR9qhuWtNOLYn%2Btzbn9tMxekKXnKHlXkXj%2FcJuvQW%2BRT%2BJeXYb6O06htJ6fx0o%2FGuykjc66AhzBw%3D%3D]
command "curl" completed successfully
upload completed successfully
parsed env
using enhanced syft sbom melange runner
configuring puller identity "720909c9f5279097d847ad02a2f24ba8f59de36a/a49c7fedc33adf69"...
running command chainctl [auth login --audience apk.cgr.dev --identity 720909c9f5279097d847ad02a2f24ba8f59de36a/a49c7fedc33adf69]
Successfully exchanged token.
Valid! Id: 720909c9f5279097d847ad02a2f24ba8f59de36a/a49c7fedc33adf69
Updates are available for chainctl (current version: 0.2.185; latest: 0.2.186). To install, please run:
    $ chainctl update
command "chainctl" completed successfully
puller identity configured successfully
puller identity configured successfully
running tests...
running command /usr/bin/dind [dockerd] in background
command "/usr/bin/dind" started successfully
running command bash [-c 
  # Retry up to 60 seconds to wait for docker to start.
  worked=false
  for i in $(seq 60); do
    if docker info >/dev/null 2>&1; then
	  worked=true
	  break
    fi
    echo "docker healthcheck failed, docker is not ready, retrying... ($i/60 seconds so far)..."
    sleep 1
  done

  if [ "$worked" = "false" ]; then
    echo "Failed to start docker after 60 seconds"
    exit 1
  fi
]
command "bash" completed successfully
melange devel with runner docker is testing:
image configuration:
  contents:
    build repositories: []
    runtime repositories: []
    repositories: []
    keyring:      []
    packages:     [verticadb-operator]
  accounts:
    runas:  
    users:
      - uid=1000(build) gid=1000
    groups:
      - gid=1000(build) members=[build]
installing verticadb-operator (25.4.0.0-r2)
installing wolfi-keys (1-r12)
installing wolfi-baselayout (20230201-r24)
installing ca-certificates-bundle (20251003-r0)
installing libgcc (15.2.0-r6)
installing glibc-locale-posix (2.42-r4)
installing glibc (2.42-r4)
installing ld-linux (2.42-r4)
installing zlib (1.3.1-r51)
installing libcrypto3 (3.6.0-r6)
installing libssl3 (3.6.0-r6)
installing apk-tools (2.14.10-r9)
installing libxcrypt (4.5.2-r0)
installing libcrypt1 (2.42-r4)
installing busybox (1.37.0-r50)
installing wolfi-base (1-r7)
layer digest: sha256:5b7016fb92517ac4fc31bb4e96be66ddc4bddf025859f5a0bd563fe1ba262db1
layer diffID: sha256:4242b847164d44f4dc19524b80fccd1791db9836e20bb43bc916c4cc8d9a066f
saving OCI image locally: apko.local/cache:e3ecaa9a0838936e503c4a5b427f915ac2eece00a9c1269a42855405a8832eae
tagging local image apko.local/cache:e3ecaa9a0838936e503c4a5b427f915ac2eece00a9c1269a42855405a8832eae as index.docker.io/library/melange:latest
populating workspace /tmp/melange-workspace-3245084671 from verticadb-operator
running the main test pipeline
  File: /usr/bin/manager
  Size: 76036918  	Blocks: 148512     IO Block: 4096   regular file
Device: 10003fh/1048639d	Inode: 1307969     Links: 1
Access: (0755/-rwxr-xr-x)  Uid: (    0/    root)   Gid: (    0/    root)
Access: 2025-12-18 14:10:52.000000000 +0000
Modify: 2025-12-18 14:10:52.000000000 +0000
Change: 2025-12-18 14:15:41.967940732 +0000
pod 54e4f8155c5c8c9fb4b1313dd04ed44fd16dd2948e10a2b68b138174a59349b8 terminated
running test pipeline for subpackage verticadb-operator-compat
melange devel with runner docker is testing:
image configuration:
  contents:
    build repositories: []
    runtime repositories: []
    repositories: []
    keyring:      []
    packages:     [verticadb-operator-compat]
  accounts:
    runas:  
    users:
      - uid=1000(build) gid=1000
    groups:
      - gid=1000(build) members=[build]
installing verticadb-operator-compat (25.4.0.0-r2)
installing wolfi-keys (1-r12)
installing wolfi-baselayout (20230201-r24)
installing ca-certificates-bundle (20251003-r0)
installing libgcc (15.2.0-r6)
installing glibc-locale-posix (2.42-r4)
installing glibc (2.42-r4)
installing ld-linux (2.42-r4)
installing zlib (1.3.1-r51)
installing libcrypto3 (3.6.0-r6)
installing libssl3 (3.6.0-r6)
installing apk-tools (2.14.10-r9)
installing libxcrypt (4.5.2-r0)
installing libcrypt1 (2.42-r4)
installing busybox (1.37.0-r50)
installing wolfi-base (1-r7)
layer digest: sha256:840b90bba0eb88d6efaa947761316a542cf0177d79adbf4e6ae764aa7fb6b24c
layer diffID: sha256:c90d1b7e06986119de4eb9762b5fc0adc357942ba9c5fd6e6a6f2986828a344d
saving OCI image locally: apko.local/cache:4bab86b21b3b925586534fc178179ea09b0c9fa9749930862ce93fc8945d772d
tagging local image apko.local/cache:4bab86b21b3b925586534fc178179ea09b0c9fa9749930862ce93fc8945d772d as index.docker.io/library/melange:latest
pod 184730cb79a94a4185e556ecc6e6011adafd2aa126f7ef8709eac2f283a6e2c4 terminated
tests completed successfully
all tests passed

Indexes

https://apk.cgr.dev/wolfi-presubmit/9aa2eca851e99e7be7970f529b055c9a0280ce7c

Packages

Tests

More Observability

Command

cg build log \
  --build-id 6efdb6a6-26fe-4767-b33e-d82676be5732 \
  --project prod-wolfi-os \
  --cluster elastic-pre-a \
  --namespace pre-wolfi \
  --start 2025-12-18T14:12:10Z \
  --end 2025-12-18T14:25:53Z