Skip to content

feat(logstash-9.1): bump dep to remediate GHSA-wpv5-97wm-hp9c, GHSA-w9pc-fmgc-vxvw and GHSA-p543-xpfm-54cp#68458

Merged
dnegreira merged 6 commits into
wolfi-dev:mainfrom
efbar:feat/bump-deps-logstash91-20251009
Oct 9, 2025
Merged

feat(logstash-9.1): bump dep to remediate GHSA-wpv5-97wm-hp9c, GHSA-w9pc-fmgc-vxvw and GHSA-p543-xpfm-54cp#68458
dnegreira merged 6 commits into
wolfi-dev:mainfrom
efbar:feat/bump-deps-logstash91-20251009

Conversation

@efbar

@efbar efbar commented Oct 9, 2025

Copy link
Copy Markdown
Member

Signed-off-by: Francesco Bartolini francesco.bartolini@chainguard.dev

Summary

Bump Rack dependency from 3.1.16 to 3.1.17 to remediate three high-severity vulnerabilities in Rack's multipart parser:

All three vulnerabilities allow attackers to cause denial of service through memory exhaustion. The fix updates Rack to version 3.1.17 which adds proper size limits to multipart parsing operations.

Changes

  • Updated Rack version constraint in Gemfile.jruby-3.1.lock.release from >= 3.1.16 to >= 3.1.17
  • Added explicit Rack 3.1.17 requirement to Gemfile.template
  • Incremented epoch to 1

…A-w9pc-fmgc-vxvw

Signed-off-by: Francesco Bartolini <francesco.bartolini@chainguard.dev>
@efbar efbar changed the title feat(logstash-9.1): bump dep to remediate GHSA-wpv5-97wm-hp9c and GHSA-w9pc-fmgc-vxvw feat(logstash-9.1): bump dep to remediate GHSA-wpv5-97wm-hp9c, GHSA-w9pc-fmgc-vxvw and GHSA-p543-xpfm-54cp Oct 9, 2025
Signed-off-by: Francesco Bartolini <francesco.bartolini@chainguard.dev>
@octo-sts

octo-sts Bot commented Oct 9, 2025

Copy link
Copy Markdown
Contributor

🩹 Build Failed: Patch Application Failed

Reversed (or previously applied) patch detected! Assume -R? [n] Apply anyway? [n] Skipping patch. 1 out of 1 hunk ignored -- saving rejects to file opt/iamguarded/scripts/liblogstash.sh.rej

Build Details

Category Details
Build System melange
Failure Point patch -p1 command during iamguarded-compat subpackage build

Root Cause Analysis 🔍

A patch is being applied to opt/iamguarded/scripts/liblogstash.sh that has already been applied or is incompatible with the current file state. The patch system detected this and rejected the patch, causing the build pipeline to fail with exit status 1.


Was this comment helpful? Please use 👍 or 👎 reactions on this comment.

@octo-sts octo-sts Bot added the ai/skip-comment Stop AI from commenting on PR label Oct 9, 2025
efbar added 2 commits October 9, 2025 10:24
Signed-off-by: Francesco Bartolini <francesco.bartolini@chainguard.dev>
@octo-sts octo-sts Bot added the bincapz/pass bincapz/pass Bincapz (aka. malcontent) scan didn't detect any CRITICALs on the scanned packages. label Oct 9, 2025
efbar added 2 commits October 9, 2025 14:37
Signed-off-by: Francesco Bartolini <francesco.bartolini@chainguard.dev>
@efbar efbar requested a review from a team October 9, 2025 16:28
@dnegreira dnegreira merged commit 3609ec4 into wolfi-dev:main Oct 9, 2025
19 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

ai/skip-comment Stop AI from commenting on PR bincapz/pass bincapz/pass Bincapz (aka. malcontent) scan didn't detect any CRITICALs on the scanned packages.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants