janus-idp / backstage-showcase

Enterprise-ready Backstage distribution
https://showcase.janus-idp.io
Apache License 2.0
105 stars 140 forks source link

chore(deps): update dependency certifi to v2024 [security] #1376

Closed renovate[bot] closed 3 weeks ago

renovate[bot] commented 3 weeks ago

Mend Renovate

This PR contains the following updates:

Package Change Age Adoption Passing Confidence
certifi ==2023.11.17 -> ==2024.7.4 age adoption passing confidence

GitHub Vulnerability Alerts

CVE-2024-39689

Certifi 2024.07.04 removes root certificates from "GLOBALTRUST" from the root store. These are in the process of being removed from Mozilla's trust store.

GLOBALTRUST's root certificates are being removed pursuant to an investigation which identified "long-running and unresolved compliance issues". Conclusions of Mozilla's investigation can be found here.


Certifi removes GLOBALTRUST root certificate

CVE-2024-39689 / GHSA-248v-346w-9cwc

More information #### Details Certifi 2024.07.04 removes root certificates from "GLOBALTRUST" from the root store. These are in the process of being removed from Mozilla's trust store. GLOBALTRUST's root certificates are being removed pursuant to an investigation which identified "long-running and unresolved compliance issues". Conclusions of Mozilla's investigation can be found [here]( https://groups.google.com/a/mozilla.org/g/dev-security-policy/c/XpknYMPO8dI). #### Severity - CVSS Score: 7.5 / 10 (High) - Vector String: `CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N` #### References - [https://github.com/certifi/python-certifi/security/advisories/GHSA-248v-346w-9cwc](https://togithub.com/certifi/python-certifi/security/advisories/GHSA-248v-346w-9cwc) - [https://nvd.nist.gov/vuln/detail/CVE-2024-39689](https://nvd.nist.gov/vuln/detail/CVE-2024-39689) - [https://github.com/certifi/python-certifi/commit/bd8153872e9c6fc98f4023df9c2deaffea2fa463](https://togithub.com/certifi/python-certifi/commit/bd8153872e9c6fc98f4023df9c2deaffea2fa463) - [https://github.com/certifi/python-certifi](https://togithub.com/certifi/python-certifi) - [https://groups.google.com/a/mozilla.org/g/dev-security-policy/c/XpknYMPO8dI](https://groups.google.com/a/mozilla.org/g/dev-security-policy/c/XpknYMPO8dI) This data is provided by [OSV](https://osv.dev/vulnerability/GHSA-248v-346w-9cwc) and the [GitHub Advisory Database](https://togithub.com/github/advisory-database) ([CC-BY 4.0](https://togithub.com/github/advisory-database/blob/main/LICENSE.md)).

Release Notes

certifi/python-certifi (certifi) ### [`v2024.7.4`](https://togithub.com/certifi/python-certifi/compare/2024.06.02...2024.07.04) [Compare Source](https://togithub.com/certifi/python-certifi/compare/2024.06.02...2024.07.04) ### [`v2024.6.2`](https://togithub.com/certifi/python-certifi/compare/2024.02.02...2024.06.02) [Compare Source](https://togithub.com/certifi/python-certifi/compare/2024.02.02...2024.06.02) ### [`v2024.2.2`](https://togithub.com/certifi/python-certifi/compare/2023.11.17...2024.02.02) [Compare Source](https://togithub.com/certifi/python-certifi/compare/2023.11.17...2024.02.02)

Configuration

📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.



This PR has been generated by Mend Renovate. View repository job log here.

openshift-ci[bot] commented 3 weeks ago

Hi @renovate[bot]. Thanks for your PR.

I'm waiting for a janus-idp member to verify that this patch is reasonable to test. If it is, they should reply with /ok-to-test on its own line. Until that is done, I will not automatically test new commits in this PR, but the usual testing commands by org members will still work. Regular contributors should join the org to skip this step.

Once the patch is verified, the new status will be reflected by the ok-to-test label.

I understand the commands that are listed here.

Instructions for interacting with me using PR comments are available [here](https://git.k8s.io/community/contributors/guide/pull-requests.md). If you have questions or suggestions related to my behavior, please file an issue against the [kubernetes-sigs/prow](https://github.com/kubernetes-sigs/prow/issues/new?title=Prow%20issue:) repository.
github-actions[bot] commented 3 weeks ago

The image is available at: quay.io/janus-idp/backstage-showcase:pr-1376!

github-actions[bot] commented 3 weeks ago

The image is available at: quay.io/janus-idp/backstage-showcase:pr-1376!

kim-tsao commented 3 weeks ago

/ok-to-test

kim-tsao commented 3 weeks ago

verified this update does not cause dependency conflicts /lgtm /approve

sonarcloud[bot] commented 3 weeks ago

Quality Gate Passed Quality Gate passed

Issues
0 New issues
0 Accepted issues

Measures
0 Security Hotspots
0.0% Coverage on New Code
0.0% Duplication on New Code

See analysis details on SonarCloud

github-actions[bot] commented 3 weeks ago

The image is available at: quay.io/janus-idp/backstage-showcase:pr-1376!

kim-tsao commented 3 weeks ago

/lgtm

openshift-ci[bot] commented 3 weeks ago

[APPROVALNOTIFIER] This PR is APPROVED

This pull-request has been approved by: kim-tsao

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Needs approval from an approver in each of these files: - ~~[OWNERS](https://github.com/janus-idp/backstage-showcase/blob/main/OWNERS)~~ [kim-tsao] Approvers can indicate their approval by writing `/approve` in a comment Approvers can cancel approval by writing `/approve cancel` in a comment