Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

deno/1.46.2 package update #27326

Merged
merged 1 commit into from
Aug 29, 2024

Conversation

octo-sts[bot]
Copy link
Contributor

@octo-sts octo-sts bot commented Aug 29, 2024

Signed-off-by: wolfi-bot <121097084+wolfi-bot@users.noreply.github.com>
@octo-sts octo-sts bot added request-version-update request for a newer version of a package automated pr P1 This label indicates our scanning found High, Medium or Low CVEs for these packages. labels Aug 29, 2024
Copy link
Contributor

Package deno: Click to expand/collapse

Package deno:

.PKGINFO metadata:

  (
  	"""
  	# Generated by melange
  	pkgname = deno
- 	pkgver = 1.46.1-r0
+ 	pkgver = 1.46.2-r0
  	arch = x86_64
- 	size = 124538300
+ 	size = 127207998
  	origin = deno
  	pkgdesc = A modern runtime for JavaScript and TypeScript.
  	url = 
- 	commit = 1a343b0d589cba5ac780972382ec494b1beb19e5
- 	builddate = 1724350192
+ 	commit = 3aab9889f953eb479cc3e5ba8e5b458e742d1ff3
  	license = MIT
  	depend = so:ld-linux-x86-64.so.2
  	depend = so:libc.so.6
  	depend = so:libgcc_s.so.1
  	depend = so:libm.so.6
- 	provides = cmd:deno=1.46.1-r0
- 	datahash = 42dac3f307f39bb6b9de207a29bd86ce417d13908a83f5dcb9a5dbdeb1d4c5ce
+ 	provides = cmd:deno=1.46.2-r0
+ 	datahash = 04bc07c90baf64454c886139807ab18fc8fe0d3ae38b92b1c6bc0037d06dd19b
  	"""
  )

Modified: /usr/bin/deno

bincapz found differences: Click to expand/collapse

Deleted: deno/var/lib/db/sbom/deno-1.46.1-r0.spdx.json [⚠️ MEDIUM]

RISK KEY DESCRIPTION EVIDENCE
-MEDIUM net/download download files downloadLocation
-LOW ref/site/url contains embedded HTTPS URLs https://spdx.org/spdxdocs/chainguard/melange/2e194ef91c2e3b8e3534447ad000

Added: deno/var/lib/db/sbom/deno-1.46.2-r0.spdx.json [⚠️ MEDIUM]

RISK KEY DESCRIPTION EVIDENCE
+MEDIUM net/download download files downloadLocation
+LOW ref/site/url contains embedded HTTPS URLs https://spdx.org/spdxdocs/chainguard/melange/7cd68e4f32f60d36b99a002ae673

Changed: /tmp/wolfictl-apk-3332799220/deno/usr/bin/deno

1 new behaviors

RISK KEY DESCRIPTION EVIDENCE
+MEDIUM net/ssh Uses SSH (secure shell) service SSH

1 removed behaviors

RISK KEY DESCRIPTION EVIDENCE
-LOW hash/md5 Uses the MD5 signature format md5:

@octo-sts octo-sts bot enabled auto-merge (squash) August 29, 2024 20:00
@octo-sts octo-sts bot merged commit c81e391 into main Aug 29, 2024
13 checks passed
@octo-sts octo-sts bot deleted the wolfictl-73ba243b-8d46-4f01-90bb-dd502374a8c0 branch August 29, 2024 20:01
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
auto-approver-bot/approve automated pr P1 This label indicates our scanning found High, Medium or Low CVEs for these packages. request-version-update request for a newer version of a package service:bincapz/pass
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant