Skip to content

Releases: HomeLabHD/Prometheus-Eaton-UPS-Exporter

latest-dev

latest-dev Pre-release
Pre-release

Choose a tag to compare

@SoFMeRight SoFMeRight released this 15 Sep 05:56

📦 prometheus-eaton-ups-exporter — v0.9.3-dev+fa07cc0

Release type: prerelease • Commit: fa07cc0

Security: 🛡️ ⚠️ Warning — 8 high vulnerabilities detected

Image Availability

Registry Image Tags
Docker Hub docker.io/hlhd/prometheus-eaton-ups-exporter dev-fa07cc0 latest-dev
cr.pcfae.com cr.pcfae.com/hlhd/prometheus-eaton-ups-exporter dev-fa07cc0 latest-dev
GitHub Container Registry ghcr.io/homelabhd/prometheus-eaton-ups-exporter dev-fa07cc0 latest-dev
Digest pull commands & supply chain artifacts

docker.io/hlhd/prometheus-eaton-ups-exporter

docker pull docker.io/hlhd/prometheus-eaton-ups-exporter@sha256:4d9c792360570b6fb97322e4c06d8a717bf0fa553f71ef3bb11d7c0ed5dc93f5

cr.pcfae.com/hlhd/prometheus-eaton-ups-exporter

docker pull cr.pcfae.com/hlhd/prometheus-eaton-ups-exporter@sha256:4d9c792360570b6fb97322e4c06d8a717bf0fa553f71ef3bb11d7c0ed5dc93f5

ghcr.io/homelabhd/prometheus-eaton-ups-exporter

docker pull ghcr.io/homelabhd/prometheus-eaton-ups-exporter@sha256:4d9c792360570b6fb97322e4c06d8a717bf0fa553f71ef3bb11d7c0ed5dc93f5

Notable Changes

Bug Fixes

  • build: flatten to package-at-root; repair the image build (SoFMeRight)
  • repo: stop shadowing the StageFreight badge store in .gitignore (SoFMeRight)
  • config: standardize dev retention keep_last to 6 (SoFMeRight)

Refactoring

  • repo: standard src layout + pyproject; unskip the test suite (SoFMeRight)

Documentation

  • refresh generated badges (stagefreight) ×24
  • refresh generated docs and badges (stagefreight) ×2
  • refresh generated docs and badges [skip ci] (SoFMeRight) ×3

Maintenance

  • governance reconcile from gitlab.prplanit.com/PrPlanIT/MaintenancePolicy (StageFreight) ×17
  • governance reconcile from PrPlanIT/MaintenancePolicy 11066049d06cb0e071409a80bc96411b0a899d1e (StageFreight)
  • governance reconcile from PrPlanIT/MaintenancePolicy 44ce7931b90a3386783ed4f03a822f98eb8128de (StageFreight)
  • governance reconcile from PrPlanIT/MaintenancePolicy 2fcb480f6f7c686b6e35251e415249617752757b (StageFreight)
  • governance reconcile from PrPlanIT/MaintenancePolicy be6129b7d6583ac9fc8b2483c0e23fd1c67a5069 (StageFreight)
  • governance reconcile from PrPlanIT/MaintenancePolicy 643a4fdc2e87ac974407c3864a42f957fa9c56e5 (StageFreight)
  • governance reconcile from PrPlanIT/MaintenancePolicy 814d185bc7dd335963b721170a179791bce141fc (StageFreight)
  • governance reconcile from PrPlanIT/MaintenancePolicy b031763542a156f404162c2cf5ce4e4dc1e9993b (StageFreight)
  • governance reconcile from PrPlanIT/MaintenancePolicy f0f17ed74846d513cdf88dea0d0ae507a9767d8b (StageFreight)
  • governance reconcile from PrPlanIT/MaintenancePolicy b9104098abb0f250718b8a9d4cd0471f2f826868 (StageFreight)
  • governance reconcile from PrPlanIT/MaintenancePolicy 9ea11e7e8c74f1d295de5c143b5ff00a285983dc (StageFreight)
  • governance reconcile from PrPlanIT/MaintenancePolicy c552ad17f756dd83f403a28d2579cc3f40e30ac1 (StageFreight)
  • governance reconcile from PrPlanIT/MaintenancePolicy f9c9b39608f34d03ebc7f7f76a3cc85fb504c6e5 (StageFreight)
  • governance reconcile from PrPlanIT/MaintenancePolicy 6343b643622f5fdebe62c2c8ae7eeade88f7f5cd (StageFreight)
  • governance reconcile from PrPlanIT/MaintenancePolicy 1d5d5a20bd06afd542cc49718ec9139e659d1df3 (StageFreight)
  • governance reconcile from PrPlanIT/MaintenancePolicy 38257f2d3f3dae37b87336e456fa86a47a241965 (StageFreight)
  • governance reconcile from PrPlanIT/MaintenancePolicy ab63cb429e4293b8f3d5e5552b540359c0ab0e6b (StageFreight) ×2
  • governance reconcile from PrPlanIT/MaintenancePolicy 9c9a08078e3835df3be11459be82d6e9ccccde0d (StageFreight)
  • governance reconcile from PrPlanIT/MaintenancePolicy b1f099884a03cb7f2b8a4abddea030a65df2e289 (StageFreight)
  • governance reconcile from PrPlanIT/MaintenancePolicy bb237cc479294449ad895d9e767a547fdbd695db (StageFreight-HomeLabHD)
  • deps: update managed dependencies (stagefreight)
  • config: migrate to current stagefreight schema + canonical suite (SoFMeRight)
  • config: migrate to current schema (narrate; sources→forges/repos; policies→versioning/matchers; add ci.image) (SoFMeRight)

Security

🛡️ ⚠️ Warning — 8 high vulnerabilities detected

Vulnerability details (8 high, 9 medium, 1 low)
Severity CVE Package Installed Fixed Description
High CVE-2026-53612 libuuid 2.41.4-r0 2.41.6-r0 util-linux: util-linux: TOCTOU in the mount program when applying post-mount ownership/mode changes
High CVE-2026-53613 libuuid 2.41.4-r0 2.41.6-r0 util-linux: util-linux: TOCTOU in the mount program via ancestor directory swap on target path
High CVE-2026-53614 libuuid 2.41.4-r0 2.41.6-r0 util-linux: util-linux: SUID mount(8) allows nosuid/noexec bypass via LIBMOUNT_FORCE_MOUNT2
High CVE-2026-76642 libuuid 2.41.4-r0 2.41.6-r0 util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing...
High CVE-2026-78408 libuuid 2.41.4-r0 2.41.6-r1 The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve()...
High CVE-2026-78410 libuuid 2.41.4-r0 2.41.6-r0 A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount...
High GHSA-6v7p-g79w-8964 msgpack 1.1.2 1.2.1 MessagePack for Python: Out-of-bounds read / crash on Unpacker reuse after a caught error
High CVE-2025-47273 setuptools 70.3.0 78.1.1 setuptools: Path Traversal Vulnerability in setuptools PackageIndex
Medium CVE-2026-59890 setuptools 70.3.0 83.0.0 setuptools: setuptools: MANIFEST.in exclusion bypass in sdist via Unicode normalization collision (NFC/NFD)
Medium CVE-2026-17084 python 3.14.7 3.15.0rc2 The "stringprep" module didn't process characters from RFC 3454 tables B.2 or B.3 correctly: the latest Unicode codepoint attributes were used instead of the specified Unicode 3.2.0...
Medium CVE-2026-19672 python 3.14.7 The tarfile module's tar and data extraction filters created directories outside the destination for members whose name leaves the destination and returns to it, such as...
Medium CVE-2026-15806 python 3.14.7 3.15.0rc2 The HTTPPasswordMgr class in the urllib.request module, along with its subclasses HTTPPasswordMgrWithDefaultRealm and HTTPPasswordMgrWithPriorAuth, did not take the URL scheme into account when...
Medium CVE-2025-15367 python 3.14.7 3.15.0a6 The poplib module, when passed a user-controlled command, can have additional commands injected using newlines. Mitigation rejects commands containing control characters.
Medium CVE-2025-60876 busybox 1.37.0-r30 BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) and other C0 control bytes in the HTTP request-target (path/query), allowing the request line to be split and attacker-controlled headers...
Medium CVE-2025-60876 busybox-binsh 1.37.0-r30 BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) and other C0 control bytes in the HTTP request-target (path/query), allowing the request line to be split and attacker-controlled headers...
Medium CVE-2025-60876 ssl_client 1.37.0-r30 BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) and other C0 control bytes in the HTTP request-target (path/query), allowing the request line to be split and attacker-controlled headers...
Medium CVE-2026-4360 python 3.14.7 In the Tarfile.extract() function, the filter parameter is not passed properly when extracting hardlinks...
Low CVE-2026-15310 python 3.14.7 3.15.0rc2 When decompressing crafted zip files using the bzip/LZMA/Zstandard compressions, Python could use an attacker-controlled size to pre-allocate memory, possibly resulting in memory exhaustion.
---
Full changelog
  • [fa07cc0] governance reconcile from gitlab.prplanit.com/PrPlanIT/MaintenancePolicy (StageFreight)
  • [969a17e] refresh generated badges (stagefreight)
  • [e7d6fff] governance reconcile from gitlab.prplanit.com/PrPlanIT/MaintenancePolicy (StageFreight)
  • [0318fb3] refresh generated badges (stagefreight)
  • [889bf88] governance reconcile from gitlab.prplanit.com/PrPlanIT/MaintenancePolicy (StageFreight)
  • [f9db04f] refresh generated badges (stagefreight)
  • [ecb81a4] governance reconcile from gitlab.prplanit.com/PrPlanIT/MaintenancePolicy (StageFreight)
  • [212f9f5] refresh generated badges (stagefreight)
  • [5362210] governance reconcile from gitlab.prplanit.com/PrPlanIT/MaintenancePolicy (StageFreight)
  • [4c035ad] refresh generated badges (stagefreight)
  • [3bbd162] governance reconcile from gitlab.prplanit.com/PrPlanIT/MaintenancePolicy (StageFreight)
  • [49822cb] governance reconcile from gitlab.prplanit.com/...
Read more

dev-fa07cc0

dev-fa07cc0 Pre-release
Pre-release

Choose a tag to compare

@SoFMeRight SoFMeRight released this 15 Sep 05:56

📦 prometheus-eaton-ups-exporter — v0.9.3-dev+fa07cc0

Release type: prerelease • Commit: fa07cc0

Security: 🛡️ ⚠️ Warning — 8 high vulnerabilities detected

Image Availability

Registry Image Tags
Docker Hub docker.io/hlhd/prometheus-eaton-ups-exporter dev-fa07cc0 latest-dev
cr.pcfae.com cr.pcfae.com/hlhd/prometheus-eaton-ups-exporter dev-fa07cc0 latest-dev
GitHub Container Registry ghcr.io/homelabhd/prometheus-eaton-ups-exporter dev-fa07cc0 latest-dev
Digest pull commands & supply chain artifacts

docker.io/hlhd/prometheus-eaton-ups-exporter

docker pull docker.io/hlhd/prometheus-eaton-ups-exporter@sha256:4d9c792360570b6fb97322e4c06d8a717bf0fa553f71ef3bb11d7c0ed5dc93f5

cr.pcfae.com/hlhd/prometheus-eaton-ups-exporter

docker pull cr.pcfae.com/hlhd/prometheus-eaton-ups-exporter@sha256:4d9c792360570b6fb97322e4c06d8a717bf0fa553f71ef3bb11d7c0ed5dc93f5

ghcr.io/homelabhd/prometheus-eaton-ups-exporter

docker pull ghcr.io/homelabhd/prometheus-eaton-ups-exporter@sha256:4d9c792360570b6fb97322e4c06d8a717bf0fa553f71ef3bb11d7c0ed5dc93f5

Notable Changes

Bug Fixes

  • build: flatten to package-at-root; repair the image build (SoFMeRight)
  • repo: stop shadowing the StageFreight badge store in .gitignore (SoFMeRight)
  • config: standardize dev retention keep_last to 6 (SoFMeRight)

Refactoring

  • repo: standard src layout + pyproject; unskip the test suite (SoFMeRight)

Documentation

  • refresh generated badges (stagefreight) ×24
  • refresh generated docs and badges (stagefreight) ×2
  • refresh generated docs and badges [skip ci] (SoFMeRight) ×3

Maintenance

  • governance reconcile from gitlab.prplanit.com/PrPlanIT/MaintenancePolicy (StageFreight) ×17
  • governance reconcile from PrPlanIT/MaintenancePolicy 11066049d06cb0e071409a80bc96411b0a899d1e (StageFreight)
  • governance reconcile from PrPlanIT/MaintenancePolicy 44ce7931b90a3386783ed4f03a822f98eb8128de (StageFreight)
  • governance reconcile from PrPlanIT/MaintenancePolicy 2fcb480f6f7c686b6e35251e415249617752757b (StageFreight)
  • governance reconcile from PrPlanIT/MaintenancePolicy be6129b7d6583ac9fc8b2483c0e23fd1c67a5069 (StageFreight)
  • governance reconcile from PrPlanIT/MaintenancePolicy 643a4fdc2e87ac974407c3864a42f957fa9c56e5 (StageFreight)
  • governance reconcile from PrPlanIT/MaintenancePolicy 814d185bc7dd335963b721170a179791bce141fc (StageFreight)
  • governance reconcile from PrPlanIT/MaintenancePolicy b031763542a156f404162c2cf5ce4e4dc1e9993b (StageFreight)
  • governance reconcile from PrPlanIT/MaintenancePolicy f0f17ed74846d513cdf88dea0d0ae507a9767d8b (StageFreight)
  • governance reconcile from PrPlanIT/MaintenancePolicy b9104098abb0f250718b8a9d4cd0471f2f826868 (StageFreight)
  • governance reconcile from PrPlanIT/MaintenancePolicy 9ea11e7e8c74f1d295de5c143b5ff00a285983dc (StageFreight)
  • governance reconcile from PrPlanIT/MaintenancePolicy c552ad17f756dd83f403a28d2579cc3f40e30ac1 (StageFreight)
  • governance reconcile from PrPlanIT/MaintenancePolicy f9c9b39608f34d03ebc7f7f76a3cc85fb504c6e5 (StageFreight)
  • governance reconcile from PrPlanIT/MaintenancePolicy 6343b643622f5fdebe62c2c8ae7eeade88f7f5cd (StageFreight)
  • governance reconcile from PrPlanIT/MaintenancePolicy 1d5d5a20bd06afd542cc49718ec9139e659d1df3 (StageFreight)
  • governance reconcile from PrPlanIT/MaintenancePolicy 38257f2d3f3dae37b87336e456fa86a47a241965 (StageFreight)
  • governance reconcile from PrPlanIT/MaintenancePolicy ab63cb429e4293b8f3d5e5552b540359c0ab0e6b (StageFreight) ×2
  • governance reconcile from PrPlanIT/MaintenancePolicy 9c9a08078e3835df3be11459be82d6e9ccccde0d (StageFreight)
  • governance reconcile from PrPlanIT/MaintenancePolicy b1f099884a03cb7f2b8a4abddea030a65df2e289 (StageFreight)
  • governance reconcile from PrPlanIT/MaintenancePolicy bb237cc479294449ad895d9e767a547fdbd695db (StageFreight-HomeLabHD)
  • deps: update managed dependencies (stagefreight)
  • config: migrate to current stagefreight schema + canonical suite (SoFMeRight)
  • config: migrate to current schema (narrate; sources→forges/repos; policies→versioning/matchers; add ci.image) (SoFMeRight)

Security

🛡️ ⚠️ Warning — 8 high vulnerabilities detected

Vulnerability details (8 high, 9 medium, 1 low)
Severity CVE Package Installed Fixed Description
High CVE-2026-53612 libuuid 2.41.4-r0 2.41.6-r0 util-linux: util-linux: TOCTOU in the mount program when applying post-mount ownership/mode changes
High CVE-2026-53613 libuuid 2.41.4-r0 2.41.6-r0 util-linux: util-linux: TOCTOU in the mount program via ancestor directory swap on target path
High CVE-2026-53614 libuuid 2.41.4-r0 2.41.6-r0 util-linux: util-linux: SUID mount(8) allows nosuid/noexec bypass via LIBMOUNT_FORCE_MOUNT2
High CVE-2026-76642 libuuid 2.41.4-r0 2.41.6-r0 util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing...
High CVE-2026-78408 libuuid 2.41.4-r0 2.41.6-r1 The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve()...
High CVE-2026-78410 libuuid 2.41.4-r0 2.41.6-r0 A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount...
High GHSA-6v7p-g79w-8964 msgpack 1.1.2 1.2.1 MessagePack for Python: Out-of-bounds read / crash on Unpacker reuse after a caught error
High CVE-2025-47273 setuptools 70.3.0 78.1.1 setuptools: Path Traversal Vulnerability in setuptools PackageIndex
Medium CVE-2026-59890 setuptools 70.3.0 83.0.0 setuptools: setuptools: MANIFEST.in exclusion bypass in sdist via Unicode normalization collision (NFC/NFD)
Medium CVE-2026-17084 python 3.14.7 3.15.0rc2 The "stringprep" module didn't process characters from RFC 3454 tables B.2 or B.3 correctly: the latest Unicode codepoint attributes were used instead of the specified Unicode 3.2.0...
Medium CVE-2026-19672 python 3.14.7 The tarfile module's tar and data extraction filters created directories outside the destination for members whose name leaves the destination and returns to it, such as...
Medium CVE-2026-15806 python 3.14.7 3.15.0rc2 The HTTPPasswordMgr class in the urllib.request module, along with its subclasses HTTPPasswordMgrWithDefaultRealm and HTTPPasswordMgrWithPriorAuth, did not take the URL scheme into account when...
Medium CVE-2025-15367 python 3.14.7 3.15.0a6 The poplib module, when passed a user-controlled command, can have additional commands injected using newlines. Mitigation rejects commands containing control characters.
Medium CVE-2025-60876 busybox 1.37.0-r30 BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) and other C0 control bytes in the HTTP request-target (path/query), allowing the request line to be split and attacker-controlled headers...
Medium CVE-2025-60876 busybox-binsh 1.37.0-r30 BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) and other C0 control bytes in the HTTP request-target (path/query), allowing the request line to be split and attacker-controlled headers...
Medium CVE-2025-60876 ssl_client 1.37.0-r30 BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) and other C0 control bytes in the HTTP request-target (path/query), allowing the request line to be split and attacker-controlled headers...
Medium CVE-2026-4360 python 3.14.7 In the Tarfile.extract() function, the filter parameter is not passed properly when extracting hardlinks...
Low CVE-2026-15310 python 3.14.7 3.15.0rc2 When decompressing crafted zip files using the bzip/LZMA/Zstandard compressions, Python could use an attacker-controlled size to pre-allocate memory, possibly resulting in memory exhaustion.
---
Full changelog
  • [fa07cc0] governance reconcile from gitlab.prplanit.com/PrPlanIT/MaintenancePolicy (StageFreight)
  • [969a17e] refresh generated badges (stagefreight)
  • [e7d6fff] governance reconcile from gitlab.prplanit.com/PrPlanIT/MaintenancePolicy (StageFreight)
  • [0318fb3] refresh generated badges (stagefreight)
  • [889bf88] governance reconcile from gitlab.prplanit.com/PrPlanIT/MaintenancePolicy (StageFreight)
  • [f9db04f] refresh generated badges (stagefreight)
  • [ecb81a4] governance reconcile from gitlab.prplanit.com/PrPlanIT/MaintenancePolicy (StageFreight)
  • [212f9f5] refresh generated badges (stagefreight)
  • [5362210] governance reconcile from gitlab.prplanit.com/PrPlanIT/MaintenancePolicy (StageFreight)
  • [4c035ad] refresh generated badges (stagefreight)
  • [3bbd162] governance reconcile from gitlab.prplanit.com/PrPlanIT/MaintenancePolicy (StageFreight)
  • [49822cb] governance reconcile from gitlab.prplanit.com/...
Read more

dev-e7d6fff

dev-e7d6fff Pre-release
Pre-release

Choose a tag to compare

@SoFMeRight SoFMeRight released this 15 Sep 05:56

📦 prometheus-eaton-ups-exporter — v0.9.3-dev+e7d6fff

Release type: prerelease • Commit: e7d6fff

Security: 🛡️ ⚠️ Warning — 8 high vulnerabilities detected

Image Availability

Registry Image Tags
Docker Hub docker.io/hlhd/prometheus-eaton-ups-exporter dev-e7d6fff latest-dev
cr.pcfae.com cr.pcfae.com/hlhd/prometheus-eaton-ups-exporter dev-e7d6fff latest-dev
GitHub Container Registry ghcr.io/homelabhd/prometheus-eaton-ups-exporter dev-e7d6fff latest-dev
Digest pull commands & supply chain artifacts

docker.io/hlhd/prometheus-eaton-ups-exporter

docker pull docker.io/hlhd/prometheus-eaton-ups-exporter@sha256:97889c31cba8f54eb3149dd292be9896944cd5c379548244b808672886d03cee

cr.pcfae.com/hlhd/prometheus-eaton-ups-exporter

docker pull cr.pcfae.com/hlhd/prometheus-eaton-ups-exporter@sha256:97889c31cba8f54eb3149dd292be9896944cd5c379548244b808672886d03cee

ghcr.io/homelabhd/prometheus-eaton-ups-exporter

docker pull ghcr.io/homelabhd/prometheus-eaton-ups-exporter@sha256:97889c31cba8f54eb3149dd292be9896944cd5c379548244b808672886d03cee

Notable Changes

Bug Fixes

  • build: flatten to package-at-root; repair the image build (SoFMeRight)
  • repo: stop shadowing the StageFreight badge store in .gitignore (SoFMeRight)
  • config: standardize dev retention keep_last to 6 (SoFMeRight)

Refactoring

  • repo: standard src layout + pyproject; unskip the test suite (SoFMeRight)

Documentation

  • refresh generated badges (stagefreight) ×23
  • refresh generated docs and badges (stagefreight) ×2
  • refresh generated docs and badges [skip ci] (SoFMeRight) ×3

Maintenance

  • governance reconcile from gitlab.prplanit.com/PrPlanIT/MaintenancePolicy (StageFreight) ×16
  • governance reconcile from PrPlanIT/MaintenancePolicy 11066049d06cb0e071409a80bc96411b0a899d1e (StageFreight)
  • governance reconcile from PrPlanIT/MaintenancePolicy 44ce7931b90a3386783ed4f03a822f98eb8128de (StageFreight)
  • governance reconcile from PrPlanIT/MaintenancePolicy 2fcb480f6f7c686b6e35251e415249617752757b (StageFreight)
  • governance reconcile from PrPlanIT/MaintenancePolicy be6129b7d6583ac9fc8b2483c0e23fd1c67a5069 (StageFreight)
  • governance reconcile from PrPlanIT/MaintenancePolicy 643a4fdc2e87ac974407c3864a42f957fa9c56e5 (StageFreight)
  • governance reconcile from PrPlanIT/MaintenancePolicy 814d185bc7dd335963b721170a179791bce141fc (StageFreight)
  • governance reconcile from PrPlanIT/MaintenancePolicy b031763542a156f404162c2cf5ce4e4dc1e9993b (StageFreight)
  • governance reconcile from PrPlanIT/MaintenancePolicy f0f17ed74846d513cdf88dea0d0ae507a9767d8b (StageFreight)
  • governance reconcile from PrPlanIT/MaintenancePolicy b9104098abb0f250718b8a9d4cd0471f2f826868 (StageFreight)
  • governance reconcile from PrPlanIT/MaintenancePolicy 9ea11e7e8c74f1d295de5c143b5ff00a285983dc (StageFreight)
  • governance reconcile from PrPlanIT/MaintenancePolicy c552ad17f756dd83f403a28d2579cc3f40e30ac1 (StageFreight)
  • governance reconcile from PrPlanIT/MaintenancePolicy f9c9b39608f34d03ebc7f7f76a3cc85fb504c6e5 (StageFreight)
  • governance reconcile from PrPlanIT/MaintenancePolicy 6343b643622f5fdebe62c2c8ae7eeade88f7f5cd (StageFreight)
  • governance reconcile from PrPlanIT/MaintenancePolicy 1d5d5a20bd06afd542cc49718ec9139e659d1df3 (StageFreight)
  • governance reconcile from PrPlanIT/MaintenancePolicy 38257f2d3f3dae37b87336e456fa86a47a241965 (StageFreight)
  • governance reconcile from PrPlanIT/MaintenancePolicy ab63cb429e4293b8f3d5e5552b540359c0ab0e6b (StageFreight) ×2
  • governance reconcile from PrPlanIT/MaintenancePolicy 9c9a08078e3835df3be11459be82d6e9ccccde0d (StageFreight)
  • governance reconcile from PrPlanIT/MaintenancePolicy b1f099884a03cb7f2b8a4abddea030a65df2e289 (StageFreight)
  • governance reconcile from PrPlanIT/MaintenancePolicy bb237cc479294449ad895d9e767a547fdbd695db (StageFreight-HomeLabHD)
  • deps: update managed dependencies (stagefreight)
  • config: migrate to current stagefreight schema + canonical suite (SoFMeRight)
  • config: migrate to current schema (narrate; sources→forges/repos; policies→versioning/matchers; add ci.image) (SoFMeRight)

Security

🛡️ ⚠️ Warning — 8 high vulnerabilities detected

Vulnerability details (8 high, 9 medium, 1 low)
Severity CVE Package Installed Fixed Description
High CVE-2026-53612 libuuid 2.41.4-r0 2.41.6-r0 util-linux: util-linux: TOCTOU in the mount program when applying post-mount ownership/mode changes
High CVE-2026-53613 libuuid 2.41.4-r0 2.41.6-r0 util-linux: util-linux: TOCTOU in the mount program via ancestor directory swap on target path
High CVE-2026-53614 libuuid 2.41.4-r0 2.41.6-r0 util-linux: util-linux: SUID mount(8) allows nosuid/noexec bypass via LIBMOUNT_FORCE_MOUNT2
High CVE-2026-76642 libuuid 2.41.4-r0 2.41.6-r0 util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing...
High CVE-2026-78408 libuuid 2.41.4-r0 2.41.6-r1 The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve()...
High CVE-2026-78410 libuuid 2.41.4-r0 2.41.6-r0 A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount...
High GHSA-6v7p-g79w-8964 msgpack 1.1.2 1.2.1 MessagePack for Python: Out-of-bounds read / crash on Unpacker reuse after a caught error
High CVE-2025-47273 setuptools 70.3.0 78.1.1 setuptools: Path Traversal Vulnerability in setuptools PackageIndex
Medium CVE-2026-59890 setuptools 70.3.0 83.0.0 setuptools: setuptools: MANIFEST.in exclusion bypass in sdist via Unicode normalization collision (NFC/NFD)
Medium CVE-2026-17084 python 3.14.7 3.15.0rc2 The "stringprep" module didn't process characters from RFC 3454 tables B.2 or B.3 correctly: the latest Unicode codepoint attributes were used instead of the specified Unicode 3.2.0...
Medium CVE-2026-19672 python 3.14.7 The tarfile module's tar and data extraction filters created directories outside the destination for members whose name leaves the destination and returns to it, such as...
Medium CVE-2026-15806 python 3.14.7 3.15.0rc2 The HTTPPasswordMgr class in the urllib.request module, along with its subclasses HTTPPasswordMgrWithDefaultRealm and HTTPPasswordMgrWithPriorAuth, did not take the URL scheme into account when...
Medium CVE-2025-15367 python 3.14.7 3.15.0a6 The poplib module, when passed a user-controlled command, can have additional commands injected using newlines. Mitigation rejects commands containing control characters.
Medium CVE-2025-60876 busybox 1.37.0-r30 BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) and other C0 control bytes in the HTTP request-target (path/query), allowing the request line to be split and attacker-controlled headers...
Medium CVE-2025-60876 busybox-binsh 1.37.0-r30 BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) and other C0 control bytes in the HTTP request-target (path/query), allowing the request line to be split and attacker-controlled headers...
Medium CVE-2025-60876 ssl_client 1.37.0-r30 BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) and other C0 control bytes in the HTTP request-target (path/query), allowing the request line to be split and attacker-controlled headers...
Medium CVE-2026-4360 python 3.14.7 In the Tarfile.extract() function, the filter parameter is not passed properly when extracting hardlinks...
Low CVE-2026-15310 python 3.14.7 3.15.0rc2 When decompressing crafted zip files using the bzip/LZMA/Zstandard compressions, Python could use an attacker-controlled size to pre-allocate memory, possibly resulting in memory exhaustion.
---
Full changelog
  • [e7d6fff] governance reconcile from gitlab.prplanit.com/PrPlanIT/MaintenancePolicy (StageFreight)
  • [0318fb3] refresh generated badges (stagefreight)
  • [889bf88] governance reconcile from gitlab.prplanit.com/PrPlanIT/MaintenancePolicy (StageFreight)
  • [f9db04f] refresh generated badges (stagefreight)
  • [ecb81a4] governance reconcile from gitlab.prplanit.com/PrPlanIT/MaintenancePolicy (StageFreight)
  • [212f9f5] refresh generated badges (stagefreight)
  • [5362210] governance reconcile from gitlab.prplanit.com/PrPlanIT/MaintenancePolicy (StageFreight)
  • [4c035ad] refresh generated badges (stagefreight)
  • [3bbd162] governance reconcile from gitlab.prplanit.com/PrPlanIT/MaintenancePolicy (StageFreight)
  • [49822cb] governance reconcile from gitlab.prplanit.com/PrPlanIT/MaintenancePolicy (StageFreight)
  • [0b0ea2c] governance reconcile from gitlab.prplanit.com/PrPlanIT/MaintenancePolicy (StageFreight)
  • [02869f6...
Read more

v0.9.3

Choose a tag to compare

@SoFMeRight SoFMeRight released this 24 Mar 05:07

📦 prometheus-eaton-ups-exporter — v0.9.3

Release type: stable • Commit: 33422fb

Security: 🛡️ ⚠️ Warning — 3 high vulnerabilities detected

Image Availability

Registry Image Tags
Docker Hub docker.io/hlhd/prometheus-eaton-ups-exporter latest v0.9.3
Harbor cr.pcfae.com/hlhd/prometheus-eaton-ups-exporter latest v0.9.3
Digest pull commands & supply chain artifacts

docker.io/hlhd/prometheus-eaton-ups-exporter

docker pull docker.io/hlhd/prometheus-eaton-ups-exporter@sha256:4a303df0a9126eacecb941d6d19e22ddfedc2bf253bee613378dd25f5028dcf1

cr.pcfae.com/hlhd/prometheus-eaton-ups-exporter

docker pull cr.pcfae.com/hlhd/prometheus-eaton-ups-exporter@sha256:4a303df0a9126eacecb941d6d19e22ddfedc2bf253bee613378dd25f5028dcf1

Highlights

  • ci: use v-prefixed tags for stable and prerelease registry pushes

Notable Changes

Documentation

  • refresh generated docs and badges [skip ci] (SoFMeRight) ×3

CI/CD

  • use v-prefixed tags for stable and prerelease registry pushes (SoFMeRight)

Security

🛡️ ⚠️ Warning — 3 high vulnerabilities detected

Vulnerability details (3 high, 10 medium, 4 low)
Severity CVE Package Installed Fixed Description
High CVE-2026-22184 zlib 1.3.1-r2 1.3.2-r0 zlib: zlib: Arbitrary code execution via buffer overflow ...
High CVE-2026-2673 libcrypto3 3.5.5-r0 Issue summary: An OpenSSL TLS 1.3 server may fail to nego...
High CVE-2026-2673 libssl3 3.5.5-r0 Issue summary: An OpenSSL TLS 1.3 server may fail to nego...
Medium CVE-2026-27171 zlib 1.3.1-r2 1.3.2-r0 zlib before 1.3.2 allows CPU consumption via crc32_combin...
Medium CVE-2026-3644 python 3.14.3 3.15.0 The fix for CVE-2026-0672, which rejected control charact...
Medium CVE-2025-15366 python 3.14.3 3.15.0a6 The imaplib module, when passed a user-controlled command...
Medium CVE-2025-15367 python 3.14.3 3.15.0a6 The poplib module, when passed a user-controlled command,...
Medium CVE-2025-60876 busybox 1.37.0-r30 BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) ...
Medium CVE-2025-60876 busybox-binsh 1.37.0-r30 BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) ...
Medium CVE-2025-60876 ssl_client 1.37.0-r30 BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) ...
Medium CVE-2026-4224 python 3.14.3 3.15.0 When an Expat parser with a registered ElementDeclHandler...
Medium CVE-2025-12781 python 3.14.3 3.15.0 When passing data to the b64decode(), standard_b64decode(...
Medium CVE-2026-2297 python 3.14.3 3.15.0 The import hook in CPython that handles legacy *.pyc file...
Low CVE-2026-1703 pip 25.3 26.0 pip: pip: Information disclosure via path traversal when ...
Low GHSA-6vgw-5pg2-w6jp pip 25.3 26.0 pip Path Traversal vulnerability
Low CVE-2025-13462 python 3.14.3 3.15.0 The "tarfile" module would still apply normalization of A...
Low CVE-2026-3479 python 3.14.3 3.15.0 pkgutil.get_data() did not validate the resource argument...
---
Full changelog
  • [33422fb] use v-prefixed tags for stable and prerelease registry pushes (SoFMeRight)
  • [d48c413] refresh generated docs and badges [skip ci] (SoFMeRight)
  • [82d6302] refresh generated docs and badges [skip ci] (SoFMeRight)
  • [6948a67] refresh generated docs and badges [skip ci] (SoFMeRight)