Skip to content

Backport of suppressing alpine CVEs as there is no fix yet into release/1.20.x#22280

Closed
hc-github-team-consul-core wants to merge 1 commit into
release/1.20.xfrom
backport/nitin/cve-suppress/mistakenly-mighty-aphid
Closed

Backport of suppressing alpine CVEs as there is no fix yet into release/1.20.x#22280
hc-github-team-consul-core wants to merge 1 commit into
release/1.20.xfrom
backport/nitin/cve-suppress/mistakenly-mighty-aphid

Conversation

@hc-github-team-consul-core
Copy link
Copy Markdown
Collaborator

Backport

This PR is auto-generated from #22278 to be assessed for backporting due to the inclusion of the label backport/1.20.

The below text is copied from the body of the original PR.


Description

Suppressing following alpine CVEs as there is no fix yet:

CVE-2024-53427 from Alpine Linux's Security Issue Tracker in jq@1.7.1-r0

CVE-2025-31498 from Alpine Linux's Security Issue Tracker in c-ares@1.34.3-r0

CVE-2025-30258 from Alpine Linux's Security Issue Tracker in gnupg@2.4.7-r0

CVE-2025-31498 from Alpine Linux's Security Issue Tracker in c-ares@1.34.3-r0

CVE-2025-30258 from Alpine Linux's Security Issue Tracker in gnupg@2.4.7-r0

CVE-2024-53427 from Alpine Linux's Security Issue Tracker in jq@1.7.1-r0

Testing & Reproduction steps

Links

PR Checklist

  • updated test coverage
  • external facing docs updated
  • appropriate backport labels added
  • not a security concern

Overview of commits

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Auto approved Consul Bot automated PR

Copy link
Copy Markdown
Contributor

@anandmukul93 anandmukul93 left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@github-actions
Copy link
Copy Markdown

This pull request has been automatically flagged for inactivity because it has not been acted upon in the last 60 days. It will be closed if no new activity occurs in the next 30 days. Please feel free to re-open to resurrect the change if you feel this has happened by mistake. Thank you for your contributions.

@github-actions github-actions Bot added the meta/stale Automatically flagged for inactivity by stalebot label Jun 21, 2025
@github-actions
Copy link
Copy Markdown

Closing due to inactivity. If you feel this was a mistake or you wish to re-open at any time in the future, please leave a comment and it will be re-surfaced for the maintainers to review.

@github-actions github-actions Bot closed this Jul 21, 2025
@github-actions github-actions Bot deleted the backport/nitin/cve-suppress/mistakenly-mighty-aphid branch October 16, 2025 06:03
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

meta/stale Automatically flagged for inactivity by stalebot

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants