containers / prometheus-podman-exporter

Prometheus exporter for podman environments exposing containers, pods, images, volumes and networks information.
Apache License 2.0
140 stars 23 forks source link

Bump github.com/containers/podman/v5 from 5.2.4 to 5.2.5 #294

Closed dependabot[bot] closed 1 month ago

dependabot[bot] commented 1 month ago

Bumps github.com/containers/podman/v5 from 5.2.4 to 5.2.5.

Changelog

Sourced from github.com/containers/podman/v5's changelog.

5.2.5

Security

  • This release addresses CVE-2024-9675, which allows arbitrary access to the host filesystem from RUN --mount type=cache arguments to a Dockerfile being built.
  • This release also addresses CVE-2024-9676, which allows malicious images with a symlink /etc/passwd or /etc/group to potentially cause a denial of service through reading a FIFO on the host.

Misc

  • Updated Buildah to v1.37.5
  • Updated the containers/storage library to v1.55.1
Commits
  • 10c5aa7 Bump to v5.2.5
  • 62d5d47 Update release notes for 5.2.5
  • 4d2bf24 Bump c/storage to v1.55.1 and Buildah to v1.37.5
  • 6f83da2 Merge pull request #24296 from openshift-cherrypick-robot/cherry-pick-24295-t...
  • ac1a323 RPM: remove dup Provides
  • 9dc2a29 Merge pull request #24203 from openshift-cherrypick-robot/cherry-pick-24202-t...
  • 8c01f53 Packit: constrain koji and bodhi jobs to fedora package to avoid dupes
  • 99b3317 Merge pull request #24190 from mheon/bump_524
  • 3b671d5 Bump to v5.2.5-dev
  • See full diff in compare view


Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually - `@dependabot show ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)