Skip to content

Conversation

@cx-david-kesoshvili
Copy link
Contributor

No description provided.

@cx-david-kesoshvili cx-david-kesoshvili changed the title Update syft extractor 0.21.0 rpm src fix (AST-0000) Update syft extractor 0.21.0 rpm src fix (AST-117722) Nov 13, 2025
@cx-shaked-karta
Copy link
Collaborator

Logo
Checkmarx One – Scan Summary & Details1ef87577-50a7-4edf-baf8-035a2481f2a4

New Issues (2)

Checkmarx found the following issues in this Pull Request

Severity Issue Source File / Package Checkmarx Insight
HIGH CVE-2024-25621 Go-github.com/containerd/containerd-v1.7.28
detailsRecommended version: v1.7.29
Description: containerd is an open-source container runtime. Versions 0.1.0 through 1.7.28, 2.0.0-beta.0 through 2.0.6, 2.1.0-beta.0 through 2.1.4 and 2.2.0-bet...
Attack Vector: LOCAL
Attack Complexity: LOW

ID: JuWn6LBNCtDgOTvFOK%2BrNWVyhDh8O3qSWklP6M4t8Gw%3D
Vulnerable Package
HIGH CVE-2024-25621 Go-github.com/containerd/containerd/v2-v2.1.2
detailsRecommended version: v2.1.5
Description: containerd is an open-source container runtime. Versions 0.1.0 through 1.7.28, 2.0.0-beta.0 through 2.0.6, 2.1.0-beta.0 through 2.1.4 and 2.2.0-bet...
Attack Vector: LOCAL
Attack Complexity: LOW

ID: qEKxeOCJnGAqSIfRJj4pPLQ3wH68s%2FcjB5PqiSAKkLs%3D
Vulnerable Package

Use @Checkmarx to reach out to us for assistance.

Just send a PR comment with @Checkmarx followed by a natural language request.

Examples: @Checkmarx how are you able to help me? @Checkmarx rescan this PR

@cx-david-kesoshvili cx-david-kesoshvili enabled auto-merge (squash) November 13, 2025 09:31
@cx-david-kesoshvili cx-david-kesoshvili merged commit ef48919 into main Nov 13, 2025
4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants