mikefarah / yq

yq is a portable command-line YAML, JSON, XML, CSV, TOML and properties processor
https://mikefarah.gitbook.io/yq/
MIT License
12.33k stars 602 forks source link

Rebuild Alpine-based image to address CVE-2024-6119 #2162

Closed psmolkin closed 1 week ago

psmolkin commented 1 month ago

The latest version of yq image contains the following vulnerabilities: CVE-2024-6119:

Version of yq: (4.44.3) Operating system: Alpine 3.20 Installed via: docker

Additional context The latest Alpine 3.20 build already includes the patched versions of the affected libraries, so only a rebuild is required.

mikefarah commented 1 week ago

Fixed in 4.44.5