Skip to content
This repository was archived by the owner on Jan 7, 2026. It is now read-only.

Commit 4bcfd19

Browse files
doc(flux-source-controller): Add pending-upstream-fix event for GHSA-f83f-xpx7-ffpw (#27867)
Signed-off-by: Ankush Pathak <ankush.pathak@chainguard.dev>
1 parent 4adb815 commit 4bcfd19

1 file changed

Lines changed: 4 additions & 0 deletions

File tree

flux-source-controller.advisories.yaml

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1001,6 +1001,10 @@ advisories:
10011001
componentType: go-module
10021002
componentLocation: /usr/bin/source-controller
10031003
scanner: grype
1004+
- timestamp: 2025-12-11T09:01:54Z
1005+
type: pending-upstream-fix
1006+
data:
1007+
note: Remediating this vulnerability requires upgrading github.com/sigstore/fulcio to 1.8.3. github.com/sigstore/fulcio is a transitive dependency and attempting to upgrade results in build failures.
10041008

10051009
- id: CGA-w436-9442-r362
10061010
aliases:

0 commit comments

Comments
 (0)