atomist-skills / lein-deps-tree-skill

Skill to open/close issues based on confusing dependencies
Other
0 stars 0 forks source link

Vulnerability update in gcr.io/atomist-container-skills/lein-deps-tree-skill (branch master) #150

Closed atomist[bot] closed 2 years ago

atomist[bot] commented 2 years ago
Vulnerabilities

Following vulnerability change detected in image gcr.io/atomist-container-skills/lein-deps-tree-skill from branch master:

New vulnerability
CVESeverityCVSSPackagesFixLine
Image gcr.io/atomist-container-skills/lein-deps-tree-skill
CVE-2021-42740critical9.8shell-quote 1.7.218
Details Commit ab9623871f376b40cf798e0cf45c9c44fa6380b5
Image gcr.io/atomist-container-skills/lein-deps-tree-skill
Tag ab9623871f376b40cf798e0cf45c9c44fa6380b5
Digest sha256:78c712fb552d082e34bba6bbdfe80db845d82317b18ec8a878dbd9a14bea9c9f
Scanned October 31, 2021, 12:05 AM UTC
atomist[bot] commented 2 years ago
Vulnerabilities

Following vulnerability changes detected in image gcr.io/atomist-container-skills/lein-deps-tree-skill from branch master:

New vulnerabilities
CVESeverityCVSSPackagesFixLine
Base image gcr.io/atomist-container-skills/clojure-base:openjdk11
CVE-2021-35942critical9.1libc-bin 2.28-10
libc-bin 2.28-10
libc6 2.28-10
libc6 2.28-10
1
CVE-2021-33574critical9.8libc-bin 2.28-10
libc-bin 2.28-10
libc6 2.28-10
libc6 2.28-10
1
CVE-2021-29940critical9.8through 2.3.81
CVE-2021-26291critical9.1maven-artifact 3.6.1
maven-artifact 3.6.3
maven-builder-support 3.6.1
maven-builder-support 3.6.3
maven-core 3.6.3
maven-model 3.6.1
maven-model 3.6.3
maven-model-builder 3.6.1
maven-model-builder 3.6.3
maven-repository-metadata 3.6.1
maven-repository-metadata 3.6.3
maven-resolver-api 1.3.3
maven-resolver-api 1.6.1
maven-resolver-api 1.6.2
maven-resolver-connector-basic 1.3.3
maven-resolver-connector-basic 1.6.1
maven-resolver-connector-basic 1.6.2
maven-resolver-impl 1.3.3
maven-resolver-impl 1.6.1
maven-resolver-impl 1.6.2
maven-resolver-provider 3.6.1
maven-resolver-provider 3.6.3
maven-resolver-spi 1.3.3
maven-resolver-spi 1.6.1
maven-resolver-spi 1.6.2
maven-resolver-transport-file 1.3.3
maven-resolver-transport-file 1.6.1
maven-resolver-transport-http 1.3.3
maven-resolver-transport-http 1.6.1
maven-resolver-transport-wagon 1.3.3
maven-resolver-transport-wagon 1.6.2
maven-resolver-util 1.3.3
maven-resolver-util 1.6.1
maven-resolver-util 1.6.2
maven-settings 3.6.3
maven-settings-builder 3.6.3
maven-shared-utils 3.2.1
1
CVE-2021-22930critical9.8nodejs 12.22.1-1nodesource1
nodejs 12.22.1-1nodesource1
1
CVE-2021-3711critical9.8libssl1.1 1.1.1d-0+deb10u6 > 1.1.1d-0+deb10u7
libssl1.1 1.1.1d-0+deb10u6 > 1.1.1d-0+deb10u7
openssl 1.1.1d-0+deb10u6 > 1.1.1d-0+deb10u7
openssl 1.1.1d-0+deb10u6 > 1.1.1d-0+deb10u7
x1
CVE-2021-3177critical9.8libpython2.7-minimal 2.7.16-2+deb10u1
libpython2.7-minimal 2.7.16-2+deb10u1
python2.7-minimal 2.7.16-2+deb10u1
python2.7-minimal 2.7.16-2+deb10u1
1
CVE-2020-27619critical9.8libpython3.7-minimal 3.7.3-2+deb10u3
libpython3.7-minimal 3.7.3-2+deb10u3
libpython3.7-stdlib 3.7.3-2+deb10u3
libpython3.7-stdlib 3.7.3-2+deb10u3
python3.7 3.7.3-2+deb10u3
python3.7 3.7.3-2+deb10u3
python3.7-minimal 3.7.3-2+deb10u3
python3.7-minimal 3.7.3-2+deb10u3
1
CVE-2020-11656critical9.8libsqlite3-0 3.27.2-3+deb10u1
libsqlite3-0 3.27.2-3+deb10u1
1
CVE-2019-1010022critical9.8libc-bin 2.28-10
libc-bin 2.28-10
libc6 2.28-10
libc6 2.28-10
1
CVE-2019-9893critical9.8libseccomp2 2.3.3-4
libseccomp2 2.3.3-4
1
CVE-2021-40330high7.5git 1:2.20.1-2+deb10u3
git 1:2.20.1-2+deb10u3
git-man 1:2.20.1-2+deb10u3
git-man 1:2.20.1-2+deb10u3
1
CVE-2021-39537high8.8libncursesw6 6.1+20181013-2+deb10u2
libncursesw6 6.1+20181013-2+deb10u2
libtinfo6 6.1+20181013-2+deb10u2
libtinfo6 6.1+20181013-2+deb10u2
ncurses-base 6.1+20181013-2+deb10u2
ncurses-base 6.1+20181013-2+deb10u2
ncurses-bin 6.1+20181013-2+deb10u2
ncurses-bin 6.1+20181013-2+deb10u2
1
CVE-2021-37714high7.5jsoup 1.11.3 > 1.14.2
jsoup 1.12.1 > 1.14.2
org.jsoup:jsoup 1.11.3 > 1.14.2
org.jsoup:jsoup 1.12.1 > 1.14.2
x1
CVE-2021-37713high8.6tar 4.4.13 > 4.4.18x1
CVE-2021-37712high8.6tar 4.4.13 > 4.4.18x1
CVE-2021-37701high8.6tar 4.4.13 > 4.4.16x1
CVE-2021-36690high7.5libsqlite3-0 3.27.2-3+deb10u1
libsqlite3-0 3.27.2-3+deb10u1
1
CVE-2021-36222high7.5libgssapi-krb5-2 1.17-3+deb10u1 > 1.17-3+deb10u2
libgssapi-krb5-2 1.17-3+deb10u1 > 1.17-3+deb10u2
libk5crypto3 1.17-3+deb10u1 > 1.17-3+deb10u2
libk5crypto3 1.17-3+deb10u1 > 1.17-3+deb10u2
libkrb5-3 1.17-3+deb10u1 > 1.17-3+deb10u2
libkrb5-3 1.17-3+deb10u1 > 1.17-3+deb10u2
libkrb5support0 1.17-3+deb10u1 > 1.17-3+deb10u2
libkrb5support0 1.17-3+deb10u1 > 1.17-3+deb10u2
x1
CVE-2021-32804high8.1tar 4.4.13 > 4.4.14x1
CVE-2021-32803high8.1tar 4.4.13 > 4.4.15x1
CVE-2021-28165high7.5jetty-client 9.4.36.v20210114
jetty-http 9.4.36.v20210114
jetty-io 9.4.36.v20210114 > 9.4.39
jetty-util 9.4.36.v20210114
org.eclipse.jetty:jetty-client 9.4.36.v20210114 > 9.4.39.v20210325, 10.0.2, 11.0.2
org.eclipse.jetty:jetty-http 9.4.36.v20210114 > 9.4.39.v20210325, 10.0.2, 11.0.2
org.eclipse.jetty:jetty-io 9.4.36.v20210114 > 10.0.2, 9.4.39, 11.0.2
org.eclipse.jetty:jetty-util 9.4.36.v20210114 > 9.4.39.v20210325, 10.0.2, 11.0.2
1
CVE-2021-27290high7.5ssri 6.0.1 > 6.0.2x1
CVE-2021-23343high7.5path-parse 1.0.6 > 1.0.7x1
CVE-2021-22946high7.5libcurl3-gnutls 7.64.0-4+deb10u2
libcurl3-gnutls 7.64.0-4+deb10u2
1
CVE-2021-21300high7.5git 1:2.20.1-2+deb10u3
git 1:2.20.1-2+deb10u3
git-man 1:2.20.1-2+deb10u3
git-man 1:2.20.1-2+deb10u3
1
CVE-2021-3807high7.5ansi-regex 3.0.0 > 5.0.1
ansi-regex 4.1.0 > 5.0.1
x1
CVE-2021-3712high7.4libssl1.1 1.1.1d-0+deb10u6 > 1.1.1d-0+deb10u7
libssl1.1 1.1.1d-0+deb10u6 > 1.1.1d-0+deb10u7
openssl 1.1.1d-0+deb10u6 > 1.1.1d-0+deb10u7
openssl 1.1.1d-0+deb10u6 > 1.1.1d-0+deb10u7
x1
CVE-2021-3326high7.5libc-bin 2.28-10
libc-bin 2.28-10
libc6 2.28-10
libc6 2.28-10
1
CVE-2020-11080high7.5libnghttp2-14 1.36.0-2+deb10u1
libnghttp2-14 1.36.0-2+deb10u1
1
CVE-2020-8116high7.3dot-prop 4.2.11
CVE-2020-6096high8.1libc-bin 2.28-10
libc-bin 2.28-10
libc6 2.28-10
libc6 2.28-10
1
CVE-2020-1752high7libc-bin 2.28-10
libc-bin 2.28-10
libc6 2.28-10
libc6 2.28-10
1
CVE-2020-1751high7libc-bin 2.28-10
libc-bin 2.28-10
libc6 2.28-10
libc6 2.28-10
1
CVE-2019-1010023high8.8libc-bin 2.28-10
libc-bin 2.28-10
libc6 2.28-10
libc6 2.28-10
1
CVE-2019-20907high7.5libpython2.7-minimal 2.7.16-2+deb10u1
libpython2.7-minimal 2.7.16-2+deb10u1
python2.7-minimal 2.7.16-2+deb10u1
python2.7-minimal 2.7.16-2+deb10u1
1
CVE-2019-20838high7.5libpcre3 2:8.39-12
libpcre3 2:8.39-12
1
CVE-2019-20454high7.5libpcre2-8-0 10.32-5
libpcre2-8-0 10.32-5
1
CVE-2019-19882high7.8login 1:4.5-1.1
login 1:4.5-1.1
passwd 1:4.5-1.1
passwd 1:4.5-1.1
1
CVE-2019-19603high7.5libsqlite3-0 3.27.2-3+deb10u1
libsqlite3-0 3.27.2-3+deb10u1
1
CVE-2019-19244high7.5libsqlite3-0 3.27.2-3+deb10u1
libsqlite3-0 3.27.2-3+deb10u1
1
CVE-2019-18276high7.8bash 5.0-4
bash 5.0-4
1
CVE-2019-17543high8.1liblz4-1 1.8.3-1+deb10u1
liblz4-1 1.8.3-1+deb10u1
1
CVE-2019-17498high8.1libssh2-1 1.8.0-2.1
libssh2-1 1.8.0-2.1
1
CVE-2019-15847high7.5gcc-8-base 8.3.0-6
gcc-8-base 8.3.0-6
libgcc1 1:8.3.0-6
libgcc1 1:8.3.0-6
libgcc1 8.3.0-6
libstdc++6 8.3.0-6
libstdc++6 8.3.0-6
1
CVE-2019-14855high7.5dirmngr 2.2.12-1+deb10u1
dirmngr 2.2.12-1+deb10u1
gnupg 2.2.12-1+deb10u1
gnupg 2.2.12-1+deb10u1
gnupg-l10n 2.2.12-1+deb10u1
gnupg-l10n 2.2.12-1+deb10u1
gnupg-utils 2.2.12-1+deb10u1
gnupg-utils 2.2.12-1+deb10u1
gpg 2.2.12-1+deb10u1
gpg 2.2.12-1+deb10u1
gpg-agent 2.2.12-1+deb10u1
gpg-agent 2.2.12-1+deb10u1
gpg-wks-client 2.2.12-1+deb10u1
gpg-wks-client 2.2.12-1+deb10u1
gpg-wks-server 2.2.12-1+deb10u1
gpg-wks-server 2.2.12-1+deb10u1
gpgconf 2.2.12-1+deb10u1
gpgconf 2.2.12-1+deb10u1
gpgsm 2.2.12-1+deb10u1
gpgsm 2.2.12-1+deb10u1
gpgv 2.2.12-1+deb10u1
gpgv 2.2.12-1+deb10u1
1
CVE-2019-13115high8.1libssh2-1 1.8.0-2.1
libssh2-1 1.8.0-2.1
1
CVE-2019-12290high7.5libidn2-0 2.0.5-1+deb10u1
libidn2-0 2.0.5-1+deb10u1
1
CVE-2019-9923high7.5tar 1.30+dfsg-6
tar 1.30+dfsg-6
1
CVE-2019-9674high7.5libpython2.7-minimal 2.7.16-2+deb10u1
libpython2.7-minimal 2.7.16-2+deb10u1
libpython3.7-minimal 3.7.3-2+deb10u3
libpython3.7-minimal 3.7.3-2+deb10u3
libpython3.7-stdlib 3.7.3-2+deb10u3
libpython3.7-stdlib 3.7.3-2+deb10u3
python2.7-minimal 2.7.16-2+deb10u1
python2.7-minimal 2.7.16-2+deb10u1
python3.7 3.7.3-2+deb10u3
python3.7 3.7.3-2+deb10u3
python3.7-minimal 3.7.3-2+deb10u3
python3.7-minimal 3.7.3-2+deb10u3
1
CVE-2019-9192high7.5libc-bin 2.28-10
libc-bin 2.28-10
libc6 2.28-10
libc6 2.28-10
1
CVE-2019-3844high7.8libsystemd0 241-7~deb10u7
libsystemd0 241-7~deb10u7
libudev1 241-7~deb10u7
libudev1 241-7~deb10u7
1
CVE-2019-3843high7.8libsystemd0 241-7~deb10u7
libsystemd0 241-7~deb10u7
libudev1 241-7~deb10u7
libudev1 241-7~deb10u7
1
CVE-2018-1000021high8.8git 1:2.20.1-2+deb10u3
git 1:2.20.1-2+deb10u3
git-man 1:2.20.1-2+deb10u3
git-man 1:2.20.1-2+deb10u3
1
CVE-2018-20796high7.5libc-bin 2.28-10
libc-bin 2.28-10
libc6 2.28-10
libc6 2.28-10
1
CVE-2018-12886high8.1gcc-8-base 8.3.0-6
gcc-8-base 8.3.0-6
libgcc1 1:8.3.0-6
libgcc1 1:8.3.0-6
libgcc1 8.3.0-6
libstdc++6 8.3.0-6
libstdc++6 8.3.0-6
1
CVE-2018-6829high7.5libgcrypt20 1.8.4-5+deb10u1
libgcrypt20 1.8.4-5+deb10u1
1
CVE-2018-5709high7.5libgssapi-krb5-2 1.17-3+deb10u1
libgssapi-krb5-2 1.17-3+deb10u1
libk5crypto3 1.17-3+deb10u1
libk5crypto3 1.17-3+deb10u1
libkrb5-3 1.17-3+deb10u1
libkrb5-3 1.17-3+deb10u1
libkrb5support0 1.17-3+deb10u1
libkrb5support0 1.17-3+deb10u1
1
CVE-2017-17740high7.5libldap-2.4-2 2.4.47+dfsg-3+deb10u6
libldap-2.4-2 2.4.47+dfsg-3+deb10u6
libldap-common 2.4.47+dfsg-3+deb10u6
libldap-common 2.4.47+dfsg-3+deb10u6
1
CVE-2017-17522high8.8libpython2.7-minimal 2.7.16-2+deb10u1
libpython2.7-minimal 2.7.16-2+deb10u1
libpython3.7-minimal 3.7.3-2+deb10u3
libpython3.7-minimal 3.7.3-2+deb10u3
libpython3.7-stdlib 3.7.3-2+deb10u3
libpython3.7-stdlib 3.7.3-2+deb10u3
python2.7-minimal 2.7.16-2+deb10u1
python2.7-minimal 2.7.16-2+deb10u1
python3.7 3.7.3-2+deb10u3
python3.7 3.7.3-2+deb10u3
python3.7-minimal 3.7.3-2+deb10u3
python3.7-minimal 3.7.3-2+deb10u3
1
CVE-2017-11164high7.5libpcre3 2:8.39-12
libpcre3 2:8.39-12
1
CVE-2017-7246high7.8libpcre3 2:8.39-12
libpcre3 2:8.39-12
1
CVE-2017-7245high7.8libpcre3 2:8.39-12
libpcre3 2:8.39-12
1
CVE-2015-0903high7.5editor 1.0.01
CVE-2011-4116high7.5libperl5.28 5.28.1-6+deb10u1
libperl5.28 5.28.1-6+deb10u1
perl 5.28.1-6+deb10u1
perl 5.28.1-6+deb10u1
perl 5.28.1-6+deb10u1
perl-base 5.28.1-6+deb10u1
perl-base 5.28.1-6+deb10u1
perl-modules-5.28 5.28.1-6+deb10u1
perl-modules-5.28 5.28.1-6+deb10u1
1
CVE-2008-4108high7.2python-minimal 2.7.16-1
python-minimal 2.7.16-1
python2-minimal 2.7.16-1
python2-minimal 2.7.16-1
1
CVE-2005-2541high10tar 1.30+dfsg-6
tar 1.30+dfsg-6
1
Image gcr.io/atomist-container-skills/lein-deps-tree-skill
CVE-2021-42740critical9.8shell-quote 1.7.218
CVE-2021-41720critical9.8lodash 4.17.2118
CVE-2021-26291critical9.1maven-artifact 3.5.3
maven-builder-support 3.5.3
maven-model 3.5.3
maven-model-builder 3.5.3
maven-repository-metadata 3.5.3
maven-resolver-api 1.1.1
maven-resolver-connector-basic 1.0.3
maven-resolver-impl 1.1.1
maven-resolver-provider 3.5.3
maven-resolver-spi 1.1.1
maven-resolver-transport-file 1.0.3
maven-resolver-transport-http 1.0.3
maven-resolver-transport-wagon 1.0.3
maven-resolver-util 1.1.1
18
CVE-2020-9548critical9.8com.fasterxml.jackson.core:jackson-databind 2.9.10.1 > 2.9.10.4
jackson-databind 2.9.10.1 > 2.9.10.4
x18
CVE-2020-9547critical9.8com.fasterxml.jackson.core:jackson-databind 2.9.10.1 > 2.9.10.4
jackson-databind 2.9.10.1 > 2.9.10.4
x18
CVE-2020-9546critical9.8com.fasterxml.jackson.core:jackson-databind 2.9.10.1 > 2.9.10.4
jackson-databind 2.9.10.1 > 2.9.10.4
x18
CVE-2020-8840critical9.8com.fasterxml.jackson.core:jackson-databind 2.9.10.1 > 2.9.10.3, 2.8.11.5
jackson-databind 2.9.10.1 > 2.9.10.3
x18
CVE-2019-20330critical9.8com.fasterxml.jackson.core:jackson-databind 2.9.10.1 > 2.9.10.2, 2.8.11.5
jackson-databind 2.9.10.1 > 2.9.10.2
x18
CVE-2021-37714high7.5jsoup 1.7.2 > 1.14.2
org.jsoup:jsoup 1.7.2 > 1.14.2
x18
CVE-2021-20190high8.1com.fasterxml.jackson.core:jackson-databind 2.9.10.1 > 2.9.10.7
jackson-databind 2.9.10.1 > 2.9.10.7
x18
CVE-2021-3807high7.5ansi-regex 6.0.0 > 6.0.1x18
CVE-2021-3795high7.5semver-regex 2.0.0 > 3.1.3x18
CVE-2020-36189high8.1com.fasterxml.jackson.core:jackson-databind 2.9.10.1 > 2.9.10.8
jackson-databind 2.9.10.1
18
CVE-2020-36188high8.1com.fasterxml.jackson.core:jackson-databind 2.9.10.1 > 2.9.10.8
jackson-databind 2.9.10.1
18
CVE-2020-36187high8.1com.fasterxml.jackson.core:jackson-databind 2.9.10.1 > 2.9.10.8
jackson-databind 2.9.10.1
18
CVE-2020-36186high8.1com.fasterxml.jackson.core:jackson-databind 2.9.10.1 > 2.9.10.8
jackson-databind 2.9.10.1
18
CVE-2020-36185high8.1com.fasterxml.jackson.core:jackson-databind 2.9.10.1 > 2.9.10.8
jackson-databind 2.9.10.1
18
CVE-2020-36184high8.1com.fasterxml.jackson.core:jackson-databind 2.9.10.1 > 2.9.10.8
jackson-databind 2.9.10.1
18
CVE-2020-36183high8.1com.fasterxml.jackson.core:jackson-databind 2.9.10.1 > 2.9.10.8
jackson-databind 2.9.10.1
18
CVE-2020-36182high8.1com.fasterxml.jackson.core:jackson-databind 2.9.10.1 > 2.9.10.8
jackson-databind 2.9.10.1
18
CVE-2020-36181high8.1com.fasterxml.jackson.core:jackson-databind 2.9.10.1 > 2.9.10.8
jackson-databind 2.9.10.1
18
CVE-2020-36180high8.1com.fasterxml.jackson.core:jackson-databind 2.9.10.1 > 2.9.10.8
jackson-databind 2.9.10.1
18
CVE-2020-36179high8.1com.fasterxml.jackson.core:jackson-databind 2.9.10.1 > 2.9.10.8
jackson-databind 2.9.10.1
18
CVE-2020-35728high8.1com.fasterxml.jackson.core:jackson-databind 2.9.10.1 > 2.9.10.8
jackson-databind 2.9.10.1
18
CVE-2020-35491high8.1com.fasterxml.jackson.core:jackson-databind 2.9.10.1 > 2.9.10.8
jackson-databind 2.9.10.1
18
CVE-2020-35490high8.1com.fasterxml.jackson.core:jackson-databind 2.9.10.1 > 2.9.10.8
jackson-databind 2.9.10.1
18
CVE-2020-25649high7.5com.fasterxml.jackson.core:jackson-databind 2.9.10.1 > 2.10.5.1, 2.9.10.7, 2.6.7.4
jackson-databind 2.9.10.1 > 2.9.10.7
x18
CVE-2020-24750high8.1com.fasterxml.jackson.core:jackson-databind 2.9.10.1 > 2.9.10.6
jackson-databind 2.9.10.1
18
CVE-2020-24616high8.1com.fasterxml.jackson.core:jackson-databind 2.9.10.1 > 2.9.10.6
jackson-databind 2.9.10.1
18
CVE-2020-14195high8.1com.fasterxml.jackson.core:jackson-databind 2.9.10.1 > 2.9.10.5
jackson-databind 2.9.10.1 > 2.9.10.5
x18
CVE-2020-14062high8.1com.fasterxml.jackson.core:jackson-databind 2.9.10.1 > 2.9.10.5
jackson-databind 2.9.10.1 > 2.9.10.5
x18
CVE-2020-14061high8.1com.fasterxml.jackson.core:jackson-databind 2.9.10.1 > 2.9.10.5
jackson-databind 2.9.10.1 > 2.9.10.5
x18
CVE-2020-14060high8.1com.fasterxml.jackson.core:jackson-databind 2.9.10.1 > 2.9.10.5
jackson-databind 2.9.10.1 > 2.9.10.5
x18
CVE-2020-11620high8.1com.fasterxml.jackson.core:jackson-databind 2.9.10.1 > 2.9.10.4
jackson-databind 2.9.10.1 > 2.9.10.4
x18
CVE-2020-11619high8.1com.fasterxml.jackson.core:jackson-databind 2.9.10.1 > 2.9.10.4
jackson-databind 2.9.10.1 > 2.9.10.4
x18
CVE-2020-11113high8.8com.fasterxml.jackson.core:jackson-databind 2.9.10.1 > 2.9.10.4
jackson-databind 2.9.10.1 > 2.9.10.4
x18
CVE-2020-11112high8.8com.fasterxml.jackson.core:jackson-databind 2.9.10.1 > 2.9.10.4
jackson-databind 2.9.10.1 > 2.9.10.4
x18
CVE-2020-11111high8.8com.fasterxml.jackson.core:jackson-databind 2.9.10.1 > 2.9.10.4
jackson-databind 2.9.10.1 > 2.9.10.4
x18
CVE-2020-10969high8.8com.fasterxml.jackson.core:jackson-databind 2.9.10.1 > 2.9.10.4
jackson-databind 2.9.10.1 > 2.9.10.4
x18
CVE-2020-10968high8.8com.fasterxml.jackson.core:jackson-databind 2.9.10.1 > 2.9.10.4
jackson-databind 2.9.10.1 > 2.9.10.4
x18
CVE-2020-10673high8.8com.fasterxml.jackson.core:jackson-databind 2.9.10.1 > 2.9.10.4
jackson-databind 2.9.10.1 > 2.9.10.4
x18
CVE-2020-10672high8.8com.fasterxml.jackson.core:jackson-databind 2.9.10.1 > 2.9.10.4
jackson-databind 2.9.10.1 > 2.9.10.4
x18
CVE-2017-18589high7.5cookie 0.4.018
CVE-2014-1936high7.5rc 1.2.818
Details Commit ab9623871f376b40cf798e0cf45c9c44fa6380b5
Image gcr.io/atomist-container-skills/lein-deps-tree-skill
Tag ab9623871f376b40cf798e0cf45c9c44fa6380b5
Digest sha256:78c712fb552d082e34bba6bbdfe80db845d82317b18ec8a878dbd9a14bea9c9f
Scanned November 2, 2021, 10:21 AM UTC
atomist[bot] commented 2 years ago
Vulnerabilities

Following vulnerability change detected in image gcr.io/atomist-container-skills/lein-deps-tree-skill from branch master:

Vulnerability update
CVESeverityCVSSPackagesFixLine
Base image gcr.io/atomist-container-skills/clojure-base:openjdk11
CVE-2021-43618severity_unspecified > highn/a > 7.5gmp 2:6.1.2+dfsg-41
Details Commit ab9623871f376b40cf798e0cf45c9c44fa6380b5
Image gcr.io/atomist-container-skills/lein-deps-tree-skill
Tag ab9623871f376b40cf798e0cf45c9c44fa6380b5
Digest sha256:78c712fb552d082e34bba6bbdfe80db845d82317b18ec8a878dbd9a14bea9c9f
Scanned November 19, 2021, 6:20 PM UTC
atomist[bot] commented 2 years ago
Vulnerabilities

Following vulnerability change detected in image gcr.io/atomist-container-skills/lein-deps-tree-skill from branch master:

Vulnerability update
CVESeverityCVSSPackagesFixLine
Base image gcr.io/atomist-container-skills/clojure-base:openjdk11
CVE-2020-16156medium > highn/a > 7.8perl 5.28.1-6+deb10u11
Details Commit 9dbdea745a5da30f1a1bbe182cb7cd7ca92555d4
Image gcr.io/atomist-container-skills/lein-deps-tree-skill
Tag 9dbdea745a5da30f1a1bbe182cb7cd7ca92555d4
Digest sha256:778ded81ba8cbf50e5b839263e7f42e892f43df3de156a2a746a63b5f9ea0dbe
Scanned December 18, 2021, 9:41 AM UTC
atomist[bot] commented 2 years ago
Vulnerabilities

Following vulnerability change detected in image gcr.io/atomist-container-skills/lein-deps-tree-skill from branch master:

Vulnerability update
CVESeverityCVSSPackagesFixLine
Base image gcr.io/atomist-container-skills/clojure-base:openjdk11
CVE-2021-45960severity_unspecified > highn/a > 7.5expat 2.2.6-2+deb10u11
Details Commit 9dbdea745a5da30f1a1bbe182cb7cd7ca92555d4
Image gcr.io/atomist-container-skills/lein-deps-tree-skill
Tag 9dbdea745a5da30f1a1bbe182cb7cd7ca92555d4
Digest sha256:778ded81ba8cbf50e5b839263e7f42e892f43df3de156a2a746a63b5f9ea0dbe
Scanned January 13, 2022, 2:15 PM UTC
atomist[bot] commented 2 years ago
Vulnerabilities

Following vulnerability changes detected in image gcr.io/atomist-container-skills/lein-deps-tree-skill from branch master:

Vulnerability updates
CVESeverityCVSSPackagesFixLine
Base image gcr.io/atomist-container-skills/clojure-base:openjdk11
CVE-2022-22824severity_unspecified > criticaln/a > 9.8expat 2.2.6-2+deb10u11
CVE-2022-22823severity_unspecified > criticaln/a > 9.8expat 2.2.6-2+deb10u11
CVE-2022-22822severity_unspecified > criticaln/a > 9.8expat 2.2.6-2+deb10u11
CVE-2022-22827severity_unspecified > highn/a > 8.8expat 2.2.6-2+deb10u11
CVE-2022-22826severity_unspecified > highn/a > 8.8expat 2.2.6-2+deb10u11
CVE-2022-22825severity_unspecified > highn/a > 8.8expat 2.2.6-2+deb10u11
Details Commit 9dbdea745a5da30f1a1bbe182cb7cd7ca92555d4
Image gcr.io/atomist-container-skills/lein-deps-tree-skill
Tag 9dbdea745a5da30f1a1bbe182cb7cd7ca92555d4
Digest sha256:778ded81ba8cbf50e5b839263e7f42e892f43df3de156a2a746a63b5f9ea0dbe
Scanned January 14, 2022, 2:21 PM UTC
atomist[bot] commented 2 years ago
Vulnerabilities

Following vulnerability change detected in image gcr.io/atomist-container-skills/lein-deps-tree-skill from branch master:

Vulnerability update
CVESeverityCVSSPackagesFixLine
Base image gcr.io/atomist-container-skills/clojure-base:openjdk11
CVE-2021-46143severity_unspecified > highn/a > 7.8expat 2.2.6-2+deb10u11
Details Commit 9dbdea745a5da30f1a1bbe182cb7cd7ca92555d4
Image gcr.io/atomist-container-skills/lein-deps-tree-skill
Tag 9dbdea745a5da30f1a1bbe182cb7cd7ca92555d4
Digest sha256:778ded81ba8cbf50e5b839263e7f42e892f43df3de156a2a746a63b5f9ea0dbe
Scanned January 15, 2022, 2:26 PM UTC
atomist[bot] commented 2 years ago
Vulnerabilities

Following vulnerability change detected in image gcr.io/atomist-container-skills/lein-deps-tree-skill from branch master:

New vulnerability
CVESeverityCVSSPackagesFixLine
Base image gcr.io/atomist-container-skills/clojure-base:openjdk11
CVE-2021-3999highn/aglibc 2.28-101
Details Commit 9dbdea745a5da30f1a1bbe182cb7cd7ca92555d4
Image gcr.io/atomist-container-skills/lein-deps-tree-skill
Tag 9dbdea745a5da30f1a1bbe182cb7cd7ca92555d4
Digest sha256:778ded81ba8cbf50e5b839263e7f42e892f43df3de156a2a746a63b5f9ea0dbe
Scanned January 16, 2022, 2:31 PM UTC
atomist[bot] commented 2 years ago
Vulnerabilities

Following vulnerability changes detected in image gcr.io/atomist-container-skills/lein-deps-tree-skill from branch master:

Vulnerability updates
CVESeverityCVSSPackagesFixLine
Base image gcr.io/atomist-container-skills/clojure-base:openjdk11
CVE-2022-23219severity_unspecified > highn/aglibc 2.28-101
CVE-2022-23218severity_unspecified > highn/aglibc 2.28-101
Details Commit 9dbdea745a5da30f1a1bbe182cb7cd7ca92555d4
Image gcr.io/atomist-container-skills/lein-deps-tree-skill
Tag 9dbdea745a5da30f1a1bbe182cb7cd7ca92555d4
Digest sha256:778ded81ba8cbf50e5b839263e7f42e892f43df3de156a2a746a63b5f9ea0dbe
Scanned January 19, 2022, 2:46 PM UTC
atomist[bot] commented 2 years ago
Vulnerabilities

Following vulnerability change detected in image gcr.io/atomist-container-skills/lein-deps-tree-skill from branch master:

Vulnerability update
CVESeverityCVSSPackagesFixLine
Base image gcr.io/atomist-container-skills/clojure-base:openjdk11
CVE-2022-23218high > criticaln/a > 9.8glibc 2.28-101
Details Commit 9dbdea745a5da30f1a1bbe182cb7cd7ca92555d4
Image gcr.io/atomist-container-skills/lein-deps-tree-skill
Tag 9dbdea745a5da30f1a1bbe182cb7cd7ca92555d4
Digest sha256:778ded81ba8cbf50e5b839263e7f42e892f43df3de156a2a746a63b5f9ea0dbe
Scanned January 21, 2022, 2:55 PM UTC
atomist[bot] commented 2 years ago
Vulnerabilities

Following vulnerability changes detected in image gcr.io/atomist-container-skills/lein-deps-tree-skill from branch master:

Vulnerability updates
CVESeverityCVSSPackagesFixLine
Base image gcr.io/atomist-container-skills/clojure-base:openjdk11
CVE-2022-23219high > criticaln/a > 9.8glibc 2.28-101
CVE-2021-44532medium > highn/anodejs 16.13.1-deb-1nodesource11
CVE-2021-44531medium > highn/anodejs 16.13.1-deb-1nodesource11
Details Commit 9dbdea745a5da30f1a1bbe182cb7cd7ca92555d4
Image gcr.io/atomist-container-skills/lein-deps-tree-skill
Tag 9dbdea745a5da30f1a1bbe182cb7cd7ca92555d4
Digest sha256:778ded81ba8cbf50e5b839263e7f42e892f43df3de156a2a746a63b5f9ea0dbe
Scanned January 22, 2022, 3:01 PM UTC
atomist[bot] commented 2 years ago
Vulnerabilities

Following vulnerability change detected in image gcr.io/atomist-container-skills/lein-deps-tree-skill from branch master:

Vulnerability update
CVESeverityCVSSPackagesFixLine
Base image gcr.io/atomist-container-skills/clojure-base:openjdk11
CVE-2021-44533medium > highn/anodejs 16.13.1-deb-1nodesource11
Details Commit 9dbdea745a5da30f1a1bbe182cb7cd7ca92555d4
Image gcr.io/atomist-container-skills/lein-deps-tree-skill
Tag 9dbdea745a5da30f1a1bbe182cb7cd7ca92555d4
Digest sha256:778ded81ba8cbf50e5b839263e7f42e892f43df3de156a2a746a63b5f9ea0dbe
Scanned January 27, 2022, 4:57 PM UTC
atomist[bot] commented 2 years ago
Vulnerabilities

Following vulnerability change detected in image gcr.io/atomist-container-skills/lein-deps-tree-skill from branch master:

Vulnerability update
CVESeverityCVSSPackagesFixLine
Base image gcr.io/atomist-container-skills/clojure-base:openjdk11
CVE-2022-23852medium > criticaln/a > 9.8expat 2.2.6-2+deb10u11
Details Commit 9dbdea745a5da30f1a1bbe182cb7cd7ca92555d4
Image gcr.io/atomist-container-skills/lein-deps-tree-skill
Tag 9dbdea745a5da30f1a1bbe182cb7cd7ca92555d4
Digest sha256:778ded81ba8cbf50e5b839263e7f42e892f43df3de156a2a746a63b5f9ea0dbe
Scanned January 28, 2022, 5:22 PM UTC
atomist[bot] commented 2 years ago
Vulnerabilities

Following vulnerability change detected in image gcr.io/atomist-container-skills/lein-deps-tree-skill from branch master:

Vulnerability update
CVESeverityCVSSPackagesFixLine
Base image gcr.io/atomist-container-skills/clojure-base:openjdk11
CVE-2022-23990medium > criticaln/a > 9.8expat 2.2.6-2+deb10u11
Details Commit 9dbdea745a5da30f1a1bbe182cb7cd7ca92555d4
Image gcr.io/atomist-container-skills/lein-deps-tree-skill
Tag 9dbdea745a5da30f1a1bbe182cb7cd7ca92555d4
Digest sha256:778ded81ba8cbf50e5b839263e7f42e892f43df3de156a2a746a63b5f9ea0dbe
Scanned February 1, 2022, 5:40 PM UTC
atomist[bot] commented 2 years ago

Thanks for your contribution!

This issue has been automatically marked with stale because it has not had any activity in last 50 days. It will be closed in 7 days if no further activity occurs. To prevent closing, label with defer or blocked or any of the changelog: labels.