Skip to content

build: upgrade dependencies#129

Merged
masontikhonov merged 2 commits intomasterfrom
CR-39170-security-codefresh-dind-cve-2026-39883-hig
May 6, 2026
Merged

build: upgrade dependencies#129
masontikhonov merged 2 commits intomasterfrom
CR-39170-security-codefresh-dind-cve-2026-39883-hig

Conversation

@masontikhonov
Copy link
Copy Markdown
Contributor

@masontikhonov masontikhonov commented May 4, 2026

What

This upgrades dependencies with vulnerability fixes.

Relevant tickets:
https://codefresh-io.atlassian.net/browse/CR-38257
https://codefresh-io.atlassian.net/browse/CR-39649

Labels

Assign the following labels to the PR:

security - to trigger image scanning in CI build

PR Comments

Add the following comments to the PR:

/e2e - to trigger E2E build

Security Report

Important

Current summary is in beta mode.
Please analyze the full scan report for comprehensive details.

Fixed CVEs: 3

🔴 High: 1

🟠 Medium: 1

  • CVE-2026-34743 in xz@5.8.2-r0 at unknown path

🟡 Low: 1

  • CVE-2026-27135 in nghttp2@1.68.0-r0 at unknown path

🔗 View all related Jira tickets

@masontikhonov masontikhonov self-assigned this May 4, 2026
@masontikhonov masontikhonov marked this pull request as ready for review May 4, 2026 14:56
@masontikhonov masontikhonov marked this pull request as draft May 4, 2026 14:56
@masontikhonov
Copy link
Copy Markdown
Contributor Author

/e2e

1 similar comment
@masontikhonov
Copy link
Copy Markdown
Contributor Author

/e2e

@masontikhonov masontikhonov marked this pull request as ready for review May 5, 2026 15:07
@masontikhonov masontikhonov merged commit b4c43d7 into master May 6, 2026
5 checks passed
@masontikhonov masontikhonov deleted the CR-39170-security-codefresh-dind-cve-2026-39883-hig branch May 6, 2026 14:03
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants