Releases: HomeLabHD/Prometheus-Eaton-UPS-Exporter
Release list
latest-dev
📦 prometheus-eaton-ups-exporter — v0.9.3-dev+fa07cc0
Release type: prerelease • Commit:
fa07cc0
Security: 🛡️
Image Availability
| Registry | Image | Tags |
|---|---|---|
| Docker Hub | docker.io/hlhd/prometheus-eaton-ups-exporter |
dev-fa07cc0 latest-dev |
| cr.pcfae.com | cr.pcfae.com/hlhd/prometheus-eaton-ups-exporter |
dev-fa07cc0 latest-dev |
| GitHub Container Registry | ghcr.io/homelabhd/prometheus-eaton-ups-exporter |
dev-fa07cc0 latest-dev |
Digest pull commands & supply chain artifacts
docker.io/hlhd/prometheus-eaton-ups-exporter
docker pull docker.io/hlhd/prometheus-eaton-ups-exporter@sha256:4d9c792360570b6fb97322e4c06d8a717bf0fa553f71ef3bb11d7c0ed5dc93f5
cr.pcfae.com/hlhd/prometheus-eaton-ups-exporter
docker pull cr.pcfae.com/hlhd/prometheus-eaton-ups-exporter@sha256:4d9c792360570b6fb97322e4c06d8a717bf0fa553f71ef3bb11d7c0ed5dc93f5
ghcr.io/homelabhd/prometheus-eaton-ups-exporter
docker pull ghcr.io/homelabhd/prometheus-eaton-ups-exporter@sha256:4d9c792360570b6fb97322e4c06d8a717bf0fa553f71ef3bb11d7c0ed5dc93f5
Notable Changes
Bug Fixes
- build: flatten to package-at-root; repair the image build (SoFMeRight)
- repo: stop shadowing the StageFreight badge store in .gitignore (SoFMeRight)
- config: standardize dev retention keep_last to 6 (SoFMeRight)
Refactoring
- repo: standard src layout + pyproject; unskip the test suite (SoFMeRight)
Documentation
- refresh generated badges (stagefreight) ×24
- refresh generated docs and badges (stagefreight) ×2
- refresh generated docs and badges [skip ci] (SoFMeRight) ×3
Maintenance
- governance reconcile from gitlab.prplanit.com/PrPlanIT/MaintenancePolicy (StageFreight) ×17
- governance reconcile from PrPlanIT/MaintenancePolicy 11066049d06cb0e071409a80bc96411b0a899d1e (StageFreight)
- governance reconcile from PrPlanIT/MaintenancePolicy 44ce7931b90a3386783ed4f03a822f98eb8128de (StageFreight)
- governance reconcile from PrPlanIT/MaintenancePolicy 2fcb480f6f7c686b6e35251e415249617752757b (StageFreight)
- governance reconcile from PrPlanIT/MaintenancePolicy be6129b7d6583ac9fc8b2483c0e23fd1c67a5069 (StageFreight)
- governance reconcile from PrPlanIT/MaintenancePolicy 643a4fdc2e87ac974407c3864a42f957fa9c56e5 (StageFreight)
- governance reconcile from PrPlanIT/MaintenancePolicy 814d185bc7dd335963b721170a179791bce141fc (StageFreight)
- governance reconcile from PrPlanIT/MaintenancePolicy b031763542a156f404162c2cf5ce4e4dc1e9993b (StageFreight)
- governance reconcile from PrPlanIT/MaintenancePolicy f0f17ed74846d513cdf88dea0d0ae507a9767d8b (StageFreight)
- governance reconcile from PrPlanIT/MaintenancePolicy b9104098abb0f250718b8a9d4cd0471f2f826868 (StageFreight)
- governance reconcile from PrPlanIT/MaintenancePolicy 9ea11e7e8c74f1d295de5c143b5ff00a285983dc (StageFreight)
- governance reconcile from PrPlanIT/MaintenancePolicy c552ad17f756dd83f403a28d2579cc3f40e30ac1 (StageFreight)
- governance reconcile from PrPlanIT/MaintenancePolicy f9c9b39608f34d03ebc7f7f76a3cc85fb504c6e5 (StageFreight)
- governance reconcile from PrPlanIT/MaintenancePolicy 6343b643622f5fdebe62c2c8ae7eeade88f7f5cd (StageFreight)
- governance reconcile from PrPlanIT/MaintenancePolicy 1d5d5a20bd06afd542cc49718ec9139e659d1df3 (StageFreight)
- governance reconcile from PrPlanIT/MaintenancePolicy 38257f2d3f3dae37b87336e456fa86a47a241965 (StageFreight)
- governance reconcile from PrPlanIT/MaintenancePolicy ab63cb429e4293b8f3d5e5552b540359c0ab0e6b (StageFreight) ×2
- governance reconcile from PrPlanIT/MaintenancePolicy 9c9a08078e3835df3be11459be82d6e9ccccde0d (StageFreight)
- governance reconcile from PrPlanIT/MaintenancePolicy b1f099884a03cb7f2b8a4abddea030a65df2e289 (StageFreight)
- governance reconcile from PrPlanIT/MaintenancePolicy bb237cc479294449ad895d9e767a547fdbd695db (StageFreight-HomeLabHD)
- deps: update managed dependencies (stagefreight)
- config: migrate to current stagefreight schema + canonical suite (SoFMeRight)
- config: migrate to current schema (narrate; sources→forges/repos; policies→versioning/matchers; add ci.image) (SoFMeRight)
Security
🛡️
Vulnerability details (8 high, 9 medium, 1 low)
| Severity | CVE | Package | Installed | Fixed | Description |
|---|---|---|---|---|---|
| High | CVE-2026-53612 | libuuid | 2.41.4-r0 | 2.41.6-r0 | util-linux: util-linux: TOCTOU in the mount program when applying post-mount ownership/mode changes |
| High | CVE-2026-53613 | libuuid | 2.41.4-r0 | 2.41.6-r0 | util-linux: util-linux: TOCTOU in the mount program via ancestor directory swap on target path |
| High | CVE-2026-53614 | libuuid | 2.41.4-r0 | 2.41.6-r0 | util-linux: util-linux: SUID mount(8) allows nosuid/noexec bypass via LIBMOUNT_FORCE_MOUNT2 |
| High | CVE-2026-76642 | libuuid | 2.41.4-r0 | 2.41.6-r0 | util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing... |
| High | CVE-2026-78408 | libuuid | 2.41.4-r0 | 2.41.6-r1 | The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve()... |
| High | CVE-2026-78410 | libuuid | 2.41.4-r0 | 2.41.6-r0 | A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount... |
| High | GHSA-6v7p-g79w-8964 | msgpack | 1.1.2 | 1.2.1 | MessagePack for Python: Out-of-bounds read / crash on Unpacker reuse after a caught error |
| High | CVE-2025-47273 | setuptools | 70.3.0 | 78.1.1 | setuptools: Path Traversal Vulnerability in setuptools PackageIndex |
| Medium | CVE-2026-59890 | setuptools | 70.3.0 | 83.0.0 | setuptools: setuptools: MANIFEST.in exclusion bypass in sdist via Unicode normalization collision (NFC/NFD) |
| Medium | CVE-2026-17084 | python | 3.14.7 | 3.15.0rc2 | The "stringprep" module didn't process characters from RFC 3454 tables B.2 or B.3 correctly: the latest Unicode codepoint attributes were used instead of the specified Unicode 3.2.0... |
| Medium | CVE-2026-19672 | python | 3.14.7 | — | The tarfile module's tar and data extraction filters created directories outside the destination for members whose name leaves the destination and returns to it, such as... |
| Medium | CVE-2026-15806 | python | 3.14.7 | 3.15.0rc2 | The HTTPPasswordMgr class in the urllib.request module, along with its subclasses HTTPPasswordMgrWithDefaultRealm and HTTPPasswordMgrWithPriorAuth, did not take the URL scheme into account when... |
| Medium | CVE-2025-15367 | python | 3.14.7 | 3.15.0a6 | The poplib module, when passed a user-controlled command, can have additional commands injected using newlines. Mitigation rejects commands containing control characters. |
| Medium | CVE-2025-60876 | busybox | 1.37.0-r30 | — | BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) and other C0 control bytes in the HTTP request-target (path/query), allowing the request line to be split and attacker-controlled headers... |
| Medium | CVE-2025-60876 | busybox-binsh | 1.37.0-r30 | — | BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) and other C0 control bytes in the HTTP request-target (path/query), allowing the request line to be split and attacker-controlled headers... |
| Medium | CVE-2025-60876 | ssl_client | 1.37.0-r30 | — | BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) and other C0 control bytes in the HTTP request-target (path/query), allowing the request line to be split and attacker-controlled headers... |
| Medium | CVE-2026-4360 | python | 3.14.7 | — | In the Tarfile.extract() function, the filter parameter is not passed properly when extracting hardlinks... |
| Low | CVE-2026-15310 | python | 3.14.7 | 3.15.0rc2 | When decompressing crafted zip files using the bzip/LZMA/Zstandard compressions, Python could use an attacker-controlled size to pre-allocate memory, possibly resulting in memory exhaustion. |
Full changelog
- [
fa07cc0] governance reconcile from gitlab.prplanit.com/PrPlanIT/MaintenancePolicy (StageFreight) - [
969a17e] refresh generated badges (stagefreight) - [
e7d6fff] governance reconcile from gitlab.prplanit.com/PrPlanIT/MaintenancePolicy (StageFreight) - [
0318fb3] refresh generated badges (stagefreight) - [
889bf88] governance reconcile from gitlab.prplanit.com/PrPlanIT/MaintenancePolicy (StageFreight) - [
f9db04f] refresh generated badges (stagefreight) - [
ecb81a4] governance reconcile from gitlab.prplanit.com/PrPlanIT/MaintenancePolicy (StageFreight) - [
212f9f5] refresh generated badges (stagefreight) - [
5362210] governance reconcile from gitlab.prplanit.com/PrPlanIT/MaintenancePolicy (StageFreight) - [
4c035ad] refresh generated badges (stagefreight) - [
3bbd162] governance reconcile from gitlab.prplanit.com/PrPlanIT/MaintenancePolicy (StageFreight) - [
49822cb] governance reconcile from gitlab.prplanit.com/...
dev-fa07cc0
📦 prometheus-eaton-ups-exporter — v0.9.3-dev+fa07cc0
Release type: prerelease • Commit:
fa07cc0
Security: 🛡️
Image Availability
| Registry | Image | Tags |
|---|---|---|
| Docker Hub | docker.io/hlhd/prometheus-eaton-ups-exporter |
dev-fa07cc0 latest-dev |
| cr.pcfae.com | cr.pcfae.com/hlhd/prometheus-eaton-ups-exporter |
dev-fa07cc0 latest-dev |
| GitHub Container Registry | ghcr.io/homelabhd/prometheus-eaton-ups-exporter |
dev-fa07cc0 latest-dev |
Digest pull commands & supply chain artifacts
docker.io/hlhd/prometheus-eaton-ups-exporter
docker pull docker.io/hlhd/prometheus-eaton-ups-exporter@sha256:4d9c792360570b6fb97322e4c06d8a717bf0fa553f71ef3bb11d7c0ed5dc93f5
cr.pcfae.com/hlhd/prometheus-eaton-ups-exporter
docker pull cr.pcfae.com/hlhd/prometheus-eaton-ups-exporter@sha256:4d9c792360570b6fb97322e4c06d8a717bf0fa553f71ef3bb11d7c0ed5dc93f5
ghcr.io/homelabhd/prometheus-eaton-ups-exporter
docker pull ghcr.io/homelabhd/prometheus-eaton-ups-exporter@sha256:4d9c792360570b6fb97322e4c06d8a717bf0fa553f71ef3bb11d7c0ed5dc93f5
Notable Changes
Bug Fixes
- build: flatten to package-at-root; repair the image build (SoFMeRight)
- repo: stop shadowing the StageFreight badge store in .gitignore (SoFMeRight)
- config: standardize dev retention keep_last to 6 (SoFMeRight)
Refactoring
- repo: standard src layout + pyproject; unskip the test suite (SoFMeRight)
Documentation
- refresh generated badges (stagefreight) ×24
- refresh generated docs and badges (stagefreight) ×2
- refresh generated docs and badges [skip ci] (SoFMeRight) ×3
Maintenance
- governance reconcile from gitlab.prplanit.com/PrPlanIT/MaintenancePolicy (StageFreight) ×17
- governance reconcile from PrPlanIT/MaintenancePolicy 11066049d06cb0e071409a80bc96411b0a899d1e (StageFreight)
- governance reconcile from PrPlanIT/MaintenancePolicy 44ce7931b90a3386783ed4f03a822f98eb8128de (StageFreight)
- governance reconcile from PrPlanIT/MaintenancePolicy 2fcb480f6f7c686b6e35251e415249617752757b (StageFreight)
- governance reconcile from PrPlanIT/MaintenancePolicy be6129b7d6583ac9fc8b2483c0e23fd1c67a5069 (StageFreight)
- governance reconcile from PrPlanIT/MaintenancePolicy 643a4fdc2e87ac974407c3864a42f957fa9c56e5 (StageFreight)
- governance reconcile from PrPlanIT/MaintenancePolicy 814d185bc7dd335963b721170a179791bce141fc (StageFreight)
- governance reconcile from PrPlanIT/MaintenancePolicy b031763542a156f404162c2cf5ce4e4dc1e9993b (StageFreight)
- governance reconcile from PrPlanIT/MaintenancePolicy f0f17ed74846d513cdf88dea0d0ae507a9767d8b (StageFreight)
- governance reconcile from PrPlanIT/MaintenancePolicy b9104098abb0f250718b8a9d4cd0471f2f826868 (StageFreight)
- governance reconcile from PrPlanIT/MaintenancePolicy 9ea11e7e8c74f1d295de5c143b5ff00a285983dc (StageFreight)
- governance reconcile from PrPlanIT/MaintenancePolicy c552ad17f756dd83f403a28d2579cc3f40e30ac1 (StageFreight)
- governance reconcile from PrPlanIT/MaintenancePolicy f9c9b39608f34d03ebc7f7f76a3cc85fb504c6e5 (StageFreight)
- governance reconcile from PrPlanIT/MaintenancePolicy 6343b643622f5fdebe62c2c8ae7eeade88f7f5cd (StageFreight)
- governance reconcile from PrPlanIT/MaintenancePolicy 1d5d5a20bd06afd542cc49718ec9139e659d1df3 (StageFreight)
- governance reconcile from PrPlanIT/MaintenancePolicy 38257f2d3f3dae37b87336e456fa86a47a241965 (StageFreight)
- governance reconcile from PrPlanIT/MaintenancePolicy ab63cb429e4293b8f3d5e5552b540359c0ab0e6b (StageFreight) ×2
- governance reconcile from PrPlanIT/MaintenancePolicy 9c9a08078e3835df3be11459be82d6e9ccccde0d (StageFreight)
- governance reconcile from PrPlanIT/MaintenancePolicy b1f099884a03cb7f2b8a4abddea030a65df2e289 (StageFreight)
- governance reconcile from PrPlanIT/MaintenancePolicy bb237cc479294449ad895d9e767a547fdbd695db (StageFreight-HomeLabHD)
- deps: update managed dependencies (stagefreight)
- config: migrate to current stagefreight schema + canonical suite (SoFMeRight)
- config: migrate to current schema (narrate; sources→forges/repos; policies→versioning/matchers; add ci.image) (SoFMeRight)
Security
🛡️
Vulnerability details (8 high, 9 medium, 1 low)
| Severity | CVE | Package | Installed | Fixed | Description |
|---|---|---|---|---|---|
| High | CVE-2026-53612 | libuuid | 2.41.4-r0 | 2.41.6-r0 | util-linux: util-linux: TOCTOU in the mount program when applying post-mount ownership/mode changes |
| High | CVE-2026-53613 | libuuid | 2.41.4-r0 | 2.41.6-r0 | util-linux: util-linux: TOCTOU in the mount program via ancestor directory swap on target path |
| High | CVE-2026-53614 | libuuid | 2.41.4-r0 | 2.41.6-r0 | util-linux: util-linux: SUID mount(8) allows nosuid/noexec bypass via LIBMOUNT_FORCE_MOUNT2 |
| High | CVE-2026-76642 | libuuid | 2.41.4-r0 | 2.41.6-r0 | util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing... |
| High | CVE-2026-78408 | libuuid | 2.41.4-r0 | 2.41.6-r1 | The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve()... |
| High | CVE-2026-78410 | libuuid | 2.41.4-r0 | 2.41.6-r0 | A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount... |
| High | GHSA-6v7p-g79w-8964 | msgpack | 1.1.2 | 1.2.1 | MessagePack for Python: Out-of-bounds read / crash on Unpacker reuse after a caught error |
| High | CVE-2025-47273 | setuptools | 70.3.0 | 78.1.1 | setuptools: Path Traversal Vulnerability in setuptools PackageIndex |
| Medium | CVE-2026-59890 | setuptools | 70.3.0 | 83.0.0 | setuptools: setuptools: MANIFEST.in exclusion bypass in sdist via Unicode normalization collision (NFC/NFD) |
| Medium | CVE-2026-17084 | python | 3.14.7 | 3.15.0rc2 | The "stringprep" module didn't process characters from RFC 3454 tables B.2 or B.3 correctly: the latest Unicode codepoint attributes were used instead of the specified Unicode 3.2.0... |
| Medium | CVE-2026-19672 | python | 3.14.7 | — | The tarfile module's tar and data extraction filters created directories outside the destination for members whose name leaves the destination and returns to it, such as... |
| Medium | CVE-2026-15806 | python | 3.14.7 | 3.15.0rc2 | The HTTPPasswordMgr class in the urllib.request module, along with its subclasses HTTPPasswordMgrWithDefaultRealm and HTTPPasswordMgrWithPriorAuth, did not take the URL scheme into account when... |
| Medium | CVE-2025-15367 | python | 3.14.7 | 3.15.0a6 | The poplib module, when passed a user-controlled command, can have additional commands injected using newlines. Mitigation rejects commands containing control characters. |
| Medium | CVE-2025-60876 | busybox | 1.37.0-r30 | — | BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) and other C0 control bytes in the HTTP request-target (path/query), allowing the request line to be split and attacker-controlled headers... |
| Medium | CVE-2025-60876 | busybox-binsh | 1.37.0-r30 | — | BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) and other C0 control bytes in the HTTP request-target (path/query), allowing the request line to be split and attacker-controlled headers... |
| Medium | CVE-2025-60876 | ssl_client | 1.37.0-r30 | — | BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) and other C0 control bytes in the HTTP request-target (path/query), allowing the request line to be split and attacker-controlled headers... |
| Medium | CVE-2026-4360 | python | 3.14.7 | — | In the Tarfile.extract() function, the filter parameter is not passed properly when extracting hardlinks... |
| Low | CVE-2026-15310 | python | 3.14.7 | 3.15.0rc2 | When decompressing crafted zip files using the bzip/LZMA/Zstandard compressions, Python could use an attacker-controlled size to pre-allocate memory, possibly resulting in memory exhaustion. |
Full changelog
- [
fa07cc0] governance reconcile from gitlab.prplanit.com/PrPlanIT/MaintenancePolicy (StageFreight) - [
969a17e] refresh generated badges (stagefreight) - [
e7d6fff] governance reconcile from gitlab.prplanit.com/PrPlanIT/MaintenancePolicy (StageFreight) - [
0318fb3] refresh generated badges (stagefreight) - [
889bf88] governance reconcile from gitlab.prplanit.com/PrPlanIT/MaintenancePolicy (StageFreight) - [
f9db04f] refresh generated badges (stagefreight) - [
ecb81a4] governance reconcile from gitlab.prplanit.com/PrPlanIT/MaintenancePolicy (StageFreight) - [
212f9f5] refresh generated badges (stagefreight) - [
5362210] governance reconcile from gitlab.prplanit.com/PrPlanIT/MaintenancePolicy (StageFreight) - [
4c035ad] refresh generated badges (stagefreight) - [
3bbd162] governance reconcile from gitlab.prplanit.com/PrPlanIT/MaintenancePolicy (StageFreight) - [
49822cb] governance reconcile from gitlab.prplanit.com/...
dev-e7d6fff
📦 prometheus-eaton-ups-exporter — v0.9.3-dev+e7d6fff
Release type: prerelease • Commit:
e7d6fff
Security: 🛡️
Image Availability
| Registry | Image | Tags |
|---|---|---|
| Docker Hub | docker.io/hlhd/prometheus-eaton-ups-exporter |
dev-e7d6fff latest-dev |
| cr.pcfae.com | cr.pcfae.com/hlhd/prometheus-eaton-ups-exporter |
dev-e7d6fff latest-dev |
| GitHub Container Registry | ghcr.io/homelabhd/prometheus-eaton-ups-exporter |
dev-e7d6fff latest-dev |
Digest pull commands & supply chain artifacts
docker.io/hlhd/prometheus-eaton-ups-exporter
docker pull docker.io/hlhd/prometheus-eaton-ups-exporter@sha256:97889c31cba8f54eb3149dd292be9896944cd5c379548244b808672886d03cee
cr.pcfae.com/hlhd/prometheus-eaton-ups-exporter
docker pull cr.pcfae.com/hlhd/prometheus-eaton-ups-exporter@sha256:97889c31cba8f54eb3149dd292be9896944cd5c379548244b808672886d03cee
ghcr.io/homelabhd/prometheus-eaton-ups-exporter
docker pull ghcr.io/homelabhd/prometheus-eaton-ups-exporter@sha256:97889c31cba8f54eb3149dd292be9896944cd5c379548244b808672886d03cee
Notable Changes
Bug Fixes
- build: flatten to package-at-root; repair the image build (SoFMeRight)
- repo: stop shadowing the StageFreight badge store in .gitignore (SoFMeRight)
- config: standardize dev retention keep_last to 6 (SoFMeRight)
Refactoring
- repo: standard src layout + pyproject; unskip the test suite (SoFMeRight)
Documentation
- refresh generated badges (stagefreight) ×23
- refresh generated docs and badges (stagefreight) ×2
- refresh generated docs and badges [skip ci] (SoFMeRight) ×3
Maintenance
- governance reconcile from gitlab.prplanit.com/PrPlanIT/MaintenancePolicy (StageFreight) ×16
- governance reconcile from PrPlanIT/MaintenancePolicy 11066049d06cb0e071409a80bc96411b0a899d1e (StageFreight)
- governance reconcile from PrPlanIT/MaintenancePolicy 44ce7931b90a3386783ed4f03a822f98eb8128de (StageFreight)
- governance reconcile from PrPlanIT/MaintenancePolicy 2fcb480f6f7c686b6e35251e415249617752757b (StageFreight)
- governance reconcile from PrPlanIT/MaintenancePolicy be6129b7d6583ac9fc8b2483c0e23fd1c67a5069 (StageFreight)
- governance reconcile from PrPlanIT/MaintenancePolicy 643a4fdc2e87ac974407c3864a42f957fa9c56e5 (StageFreight)
- governance reconcile from PrPlanIT/MaintenancePolicy 814d185bc7dd335963b721170a179791bce141fc (StageFreight)
- governance reconcile from PrPlanIT/MaintenancePolicy b031763542a156f404162c2cf5ce4e4dc1e9993b (StageFreight)
- governance reconcile from PrPlanIT/MaintenancePolicy f0f17ed74846d513cdf88dea0d0ae507a9767d8b (StageFreight)
- governance reconcile from PrPlanIT/MaintenancePolicy b9104098abb0f250718b8a9d4cd0471f2f826868 (StageFreight)
- governance reconcile from PrPlanIT/MaintenancePolicy 9ea11e7e8c74f1d295de5c143b5ff00a285983dc (StageFreight)
- governance reconcile from PrPlanIT/MaintenancePolicy c552ad17f756dd83f403a28d2579cc3f40e30ac1 (StageFreight)
- governance reconcile from PrPlanIT/MaintenancePolicy f9c9b39608f34d03ebc7f7f76a3cc85fb504c6e5 (StageFreight)
- governance reconcile from PrPlanIT/MaintenancePolicy 6343b643622f5fdebe62c2c8ae7eeade88f7f5cd (StageFreight)
- governance reconcile from PrPlanIT/MaintenancePolicy 1d5d5a20bd06afd542cc49718ec9139e659d1df3 (StageFreight)
- governance reconcile from PrPlanIT/MaintenancePolicy 38257f2d3f3dae37b87336e456fa86a47a241965 (StageFreight)
- governance reconcile from PrPlanIT/MaintenancePolicy ab63cb429e4293b8f3d5e5552b540359c0ab0e6b (StageFreight) ×2
- governance reconcile from PrPlanIT/MaintenancePolicy 9c9a08078e3835df3be11459be82d6e9ccccde0d (StageFreight)
- governance reconcile from PrPlanIT/MaintenancePolicy b1f099884a03cb7f2b8a4abddea030a65df2e289 (StageFreight)
- governance reconcile from PrPlanIT/MaintenancePolicy bb237cc479294449ad895d9e767a547fdbd695db (StageFreight-HomeLabHD)
- deps: update managed dependencies (stagefreight)
- config: migrate to current stagefreight schema + canonical suite (SoFMeRight)
- config: migrate to current schema (narrate; sources→forges/repos; policies→versioning/matchers; add ci.image) (SoFMeRight)
Security
🛡️
Vulnerability details (8 high, 9 medium, 1 low)
| Severity | CVE | Package | Installed | Fixed | Description |
|---|---|---|---|---|---|
| High | CVE-2026-53612 | libuuid | 2.41.4-r0 | 2.41.6-r0 | util-linux: util-linux: TOCTOU in the mount program when applying post-mount ownership/mode changes |
| High | CVE-2026-53613 | libuuid | 2.41.4-r0 | 2.41.6-r0 | util-linux: util-linux: TOCTOU in the mount program via ancestor directory swap on target path |
| High | CVE-2026-53614 | libuuid | 2.41.4-r0 | 2.41.6-r0 | util-linux: util-linux: SUID mount(8) allows nosuid/noexec bypass via LIBMOUNT_FORCE_MOUNT2 |
| High | CVE-2026-76642 | libuuid | 2.41.4-r0 | 2.41.6-r0 | util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing... |
| High | CVE-2026-78408 | libuuid | 2.41.4-r0 | 2.41.6-r1 | The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve()... |
| High | CVE-2026-78410 | libuuid | 2.41.4-r0 | 2.41.6-r0 | A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount... |
| High | GHSA-6v7p-g79w-8964 | msgpack | 1.1.2 | 1.2.1 | MessagePack for Python: Out-of-bounds read / crash on Unpacker reuse after a caught error |
| High | CVE-2025-47273 | setuptools | 70.3.0 | 78.1.1 | setuptools: Path Traversal Vulnerability in setuptools PackageIndex |
| Medium | CVE-2026-59890 | setuptools | 70.3.0 | 83.0.0 | setuptools: setuptools: MANIFEST.in exclusion bypass in sdist via Unicode normalization collision (NFC/NFD) |
| Medium | CVE-2026-17084 | python | 3.14.7 | 3.15.0rc2 | The "stringprep" module didn't process characters from RFC 3454 tables B.2 or B.3 correctly: the latest Unicode codepoint attributes were used instead of the specified Unicode 3.2.0... |
| Medium | CVE-2026-19672 | python | 3.14.7 | — | The tarfile module's tar and data extraction filters created directories outside the destination for members whose name leaves the destination and returns to it, such as... |
| Medium | CVE-2026-15806 | python | 3.14.7 | 3.15.0rc2 | The HTTPPasswordMgr class in the urllib.request module, along with its subclasses HTTPPasswordMgrWithDefaultRealm and HTTPPasswordMgrWithPriorAuth, did not take the URL scheme into account when... |
| Medium | CVE-2025-15367 | python | 3.14.7 | 3.15.0a6 | The poplib module, when passed a user-controlled command, can have additional commands injected using newlines. Mitigation rejects commands containing control characters. |
| Medium | CVE-2025-60876 | busybox | 1.37.0-r30 | — | BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) and other C0 control bytes in the HTTP request-target (path/query), allowing the request line to be split and attacker-controlled headers... |
| Medium | CVE-2025-60876 | busybox-binsh | 1.37.0-r30 | — | BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) and other C0 control bytes in the HTTP request-target (path/query), allowing the request line to be split and attacker-controlled headers... |
| Medium | CVE-2025-60876 | ssl_client | 1.37.0-r30 | — | BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) and other C0 control bytes in the HTTP request-target (path/query), allowing the request line to be split and attacker-controlled headers... |
| Medium | CVE-2026-4360 | python | 3.14.7 | — | In the Tarfile.extract() function, the filter parameter is not passed properly when extracting hardlinks... |
| Low | CVE-2026-15310 | python | 3.14.7 | 3.15.0rc2 | When decompressing crafted zip files using the bzip/LZMA/Zstandard compressions, Python could use an attacker-controlled size to pre-allocate memory, possibly resulting in memory exhaustion. |
Full changelog
- [
e7d6fff] governance reconcile from gitlab.prplanit.com/PrPlanIT/MaintenancePolicy (StageFreight) - [
0318fb3] refresh generated badges (stagefreight) - [
889bf88] governance reconcile from gitlab.prplanit.com/PrPlanIT/MaintenancePolicy (StageFreight) - [
f9db04f] refresh generated badges (stagefreight) - [
ecb81a4] governance reconcile from gitlab.prplanit.com/PrPlanIT/MaintenancePolicy (StageFreight) - [
212f9f5] refresh generated badges (stagefreight) - [
5362210] governance reconcile from gitlab.prplanit.com/PrPlanIT/MaintenancePolicy (StageFreight) - [
4c035ad] refresh generated badges (stagefreight) - [
3bbd162] governance reconcile from gitlab.prplanit.com/PrPlanIT/MaintenancePolicy (StageFreight) - [
49822cb] governance reconcile from gitlab.prplanit.com/PrPlanIT/MaintenancePolicy (StageFreight) - [
0b0ea2c] governance reconcile from gitlab.prplanit.com/PrPlanIT/MaintenancePolicy (StageFreight) - [
02869f6...
v0.9.3
📦 prometheus-eaton-ups-exporter — v0.9.3
Release type: stable • Commit:
33422fb
Security: 🛡️
Image Availability
| Registry | Image | Tags |
|---|---|---|
| Docker Hub | docker.io/hlhd/prometheus-eaton-ups-exporter |
latest v0.9.3 |
| Harbor | cr.pcfae.com/hlhd/prometheus-eaton-ups-exporter |
latest v0.9.3 |
Digest pull commands & supply chain artifacts
docker.io/hlhd/prometheus-eaton-ups-exporter
docker pull docker.io/hlhd/prometheus-eaton-ups-exporter@sha256:4a303df0a9126eacecb941d6d19e22ddfedc2bf253bee613378dd25f5028dcf1
cr.pcfae.com/hlhd/prometheus-eaton-ups-exporter
docker pull cr.pcfae.com/hlhd/prometheus-eaton-ups-exporter@sha256:4a303df0a9126eacecb941d6d19e22ddfedc2bf253bee613378dd25f5028dcf1
Highlights
- ci: use v-prefixed tags for stable and prerelease registry pushes
Notable Changes
Documentation
- refresh generated docs and badges [skip ci] (SoFMeRight) ×3
CI/CD
- use v-prefixed tags for stable and prerelease registry pushes (SoFMeRight)
Security
🛡️
Vulnerability details (3 high, 10 medium, 4 low)
| Severity | CVE | Package | Installed | Fixed | Description |
|---|---|---|---|---|---|
| High | CVE-2026-22184 | zlib | 1.3.1-r2 | 1.3.2-r0 | zlib: zlib: Arbitrary code execution via buffer overflow ... |
| High | CVE-2026-2673 | libcrypto3 | 3.5.5-r0 | — | Issue summary: An OpenSSL TLS 1.3 server may fail to nego... |
| High | CVE-2026-2673 | libssl3 | 3.5.5-r0 | — | Issue summary: An OpenSSL TLS 1.3 server may fail to nego... |
| Medium | CVE-2026-27171 | zlib | 1.3.1-r2 | 1.3.2-r0 | zlib before 1.3.2 allows CPU consumption via crc32_combin... |
| Medium | CVE-2026-3644 | python | 3.14.3 | 3.15.0 | The fix for CVE-2026-0672, which rejected control charact... |
| Medium | CVE-2025-15366 | python | 3.14.3 | 3.15.0a6 | The imaplib module, when passed a user-controlled command... |
| Medium | CVE-2025-15367 | python | 3.14.3 | 3.15.0a6 | The poplib module, when passed a user-controlled command,... |
| Medium | CVE-2025-60876 | busybox | 1.37.0-r30 | — | BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) ... |
| Medium | CVE-2025-60876 | busybox-binsh | 1.37.0-r30 | — | BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) ... |
| Medium | CVE-2025-60876 | ssl_client | 1.37.0-r30 | — | BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) ... |
| Medium | CVE-2026-4224 | python | 3.14.3 | 3.15.0 | When an Expat parser with a registered ElementDeclHandler... |
| Medium | CVE-2025-12781 | python | 3.14.3 | 3.15.0 | When passing data to the b64decode(), standard_b64decode(... |
| Medium | CVE-2026-2297 | python | 3.14.3 | 3.15.0 | The import hook in CPython that handles legacy *.pyc file... |
| Low | CVE-2026-1703 | pip | 25.3 | 26.0 | pip: pip: Information disclosure via path traversal when ... |
| Low | GHSA-6vgw-5pg2-w6jp | pip | 25.3 | 26.0 | pip Path Traversal vulnerability |
| Low | CVE-2025-13462 | python | 3.14.3 | 3.15.0 | The "tarfile" module would still apply normalization of A... |
| Low | CVE-2026-3479 | python | 3.14.3 | 3.15.0 | pkgutil.get_data() did not validate the resource argument... |
Full changelog
- [
33422fb] use v-prefixed tags for stable and prerelease registry pushes (SoFMeRight) - [
d48c413] refresh generated docs and badges [skip ci] (SoFMeRight) - [
82d6302] refresh generated docs and badges [skip ci] (SoFMeRight) - [
6948a67] refresh generated docs and badges [skip ci] (SoFMeRight)