Skip to content

Commit 4b17907

Browse files
authored
Merge pull request #1684 from snyk/CN-1326-bump-skopeo-grpc
fix(deps): bump skopeo 1.22.0 → 1.22.2 in UBI9 image to resolve gRPC CVE
2 parents e37694f + 8d7a1f3 commit 4b17907

2 files changed

Lines changed: 2 additions & 86 deletions

File tree

.snyk

Lines changed: 0 additions & 84 deletions
Original file line numberDiff line numberDiff line change
@@ -2,14 +2,6 @@
22
version: v1.25.1
33
# ignores vulnerabilities until expiry date; change duration by modifying expiry date
44
ignore:
5-
SNYK-GOLANG-GOOGLEGOLANGORGGRPC-15691172:
6-
- '*':
7-
reason: >-
8-
Container scan: skopeo binary embeds google.golang.org/grpc until
9-
distro package provides fix (>= 1.79.3). Not network-exposed as a
10-
gRPC server in this image. Re-check when skopeo/apk updates.
11-
expires: 2026-07-21T12:00:00.000Z
12-
created: 2026-03-24T12:00:00.000Z
135
SNYK-RHEL9-GNUPG2-15127565:
146
- '*':
157
reason: >-
@@ -26,11 +18,6 @@ ignore:
2618
https://access.redhat.com/security/cve/CVE-2026-24882
2719
expires: 2026-11-14T12:00:00.000Z
2820
created: 2026-01-28T21:21:43.745Z
29-
SNYK-RHEL9-VIMMINIMAL-15796062:
30-
- '*':
31-
reason: UBI 9 base image; no fix in Red Hat channels yet. Re-verify after dnf upgrade.
32-
expires: 2026-05-07T12:00:00.000Z
33-
created: 2026-03-30T12:00:00.000Z
3421
SNYK-RHEL9-VIMMINIMAL-15884750:
3522
- '*':
3623
reason: >-
@@ -39,41 +26,6 @@ ignore:
3926
https://access.redhat.com/security/cve/CVE-2026-34714
4027
expires: 2026-11-14T12:00:00.000Z
4128
created: 2026-04-07T12:00:00.000Z
42-
SNYK-RHEL9-GLIBCMINIMALLANGPACK-15885179:
43-
- '*':
44-
reason: UBI 9 base image; no fix in Red Hat channels yet. Re-verify after dnf upgrade.
45-
expires: 2026-04-23T12:00:00.000Z
46-
created: 2026-04-07T12:00:00.000Z
47-
SNYK-RHEL9-GLIBCCOMMON-15884768:
48-
- '*':
49-
reason: UBI 9 base image; no fix in Red Hat channels yet. Re-verify after dnf upgrade.
50-
expires: 2026-04-23T12:00:00.000Z
51-
created: 2026-04-07T12:00:00.000Z
52-
SNYK-RHEL9-GLIBC-15884867:
53-
- '*':
54-
reason: UBI 9 base image; no fix in Red Hat channels yet. Re-verify after dnf upgrade.
55-
expires: 2026-04-23T12:00:00.000Z
56-
created: 2026-04-07T12:00:00.000Z
57-
SNYK-RHEL9-LIBARCHIVE-15747822:
58-
- '*':
59-
reason: UBI 9 base image; no fix in Red Hat channels yet. Re-verify after dnf upgrade.
60-
expires: 2026-04-23T12:00:00.000Z
61-
created: 2026-03-24T12:00:00.000Z
62-
SNYK-RHEL9-LIBNGHTTP2-15748803:
63-
- '*':
64-
reason: UBI 9 base image; no fix in Red Hat channels yet. Re-verify after dnf upgrade.
65-
expires: 2026-04-23T12:00:00.000Z
66-
created: 2026-03-24T12:00:00.000Z
67-
SNYK-RHEL9-PYTHON3-15760267:
68-
- '*':
69-
reason: UBI 9 base image; no fix in Red Hat channels yet. Re-verify after dnf upgrade.
70-
expires: 2026-04-23T12:00:00.000Z
71-
created: 2026-03-24T12:00:00.000Z
72-
SNYK-RHEL9-PYTHON3LIBS-15760285:
73-
- '*':
74-
reason: UBI 9 base image; no fix in Red Hat channels yet. Re-verify after dnf upgrade.
75-
expires: 2026-04-23T12:00:00.000Z
76-
created: 2026-03-24T12:00:00.000Z
7729
SNYK-RHEL9-PYTHON3PIPWHEEL-14916305:
7830
- '*':
7931
reason: >-
@@ -117,40 +69,4 @@ ignore:
11769
https://access.redhat.com/security/cve/CVE-2026-24842
11870
expires: 2026-11-14T12:00:00.000Z
11971
created: 2026-01-29T16:33:39.950Z
120-
SNYK-JS-TAR-15307072:
121-
- '*':
122-
reason: >-
123-
Global npm in image bundles tar via cacache; no patched path until
124-
npm/apk update. Re-verify on image refresh.
125-
expires: 2026-04-23T12:00:00.000Z
126-
created: 2026-03-24T12:00:00.000Z
127-
SNYK-JS-TAR-15416075:
128-
- '*':
129-
reason: >-
130-
Global npm in image bundles tar via cacache; no patched path until
131-
npm/apk update. Re-verify on image refresh.
132-
expires: 2026-04-23T12:00:00.000Z
133-
created: 2026-03-24T12:00:00.000Z
134-
SNYK-JS-TAR-15456201:
135-
- '*':
136-
reason: >-
137-
Global npm in image bundles tar via cacache; no patched path until
138-
npm/apk update. Re-verify on image refresh.
139-
expires: 2026-04-23T12:00:00.000Z
140-
created: 2026-03-24T12:00:00.000Z
141-
SNYK-JS-INFLIGHT-6095116:
142-
- '*':
143-
reason: "No non-major fix available as of 2026-05-19; revisit in 7 days"
144-
expires: '2026-05-26T00:00:00.000Z'
145-
created: '2026-05-19T00:00:00.000Z'
146-
SNYK-JS-REQUEST-3361831:
147-
- '*':
148-
reason: "No fix available as of 2026-05-19; request package is deprecated and unmaintained; revisit in 7 days"
149-
expires: '2026-05-26T00:00:00.000Z'
150-
created: '2026-05-19T00:00:00.000Z'
151-
SNYK-JS-UUID-16133035:
152-
- '*':
153-
reason: "No non-major fix available as of 2026-05-19; fixedIn versions 11.1.1 and 14.0.0 are major bumps from v3; revisit in 7 days"
154-
expires: '2026-05-26T00:00:00.000Z'
155-
created: '2026-05-19T00:00:00.000Z'
15672
patch: {}

Dockerfile.ubi9

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -52,8 +52,8 @@ ARG NODE_LATEST_VERSION_TAR_GZ_FILE_SHASUM256
5252
ARG DUMB_INIT_VERSION=1.2.5
5353
ARG DUMB_INIT_BINARY_FILE_SHASUM256=e874b55f3279ca41415d290c512a7ba9d08f98041b28ae7c2acb19a545f1c4df
5454
# https://github.com/lework/skopeo-binary/releases
55-
ARG SKOPEO_VERSION=1.22.0
56-
ARG SKOPEO_BINARY_FILE_SHASUM256=397708bef1afa0defdc041bb0d3684570d97135076370257438c871600c1c587
55+
ARG SKOPEO_VERSION=1.22.2
56+
ARG SKOPEO_BINARY_FILE_SHASUM256=e8036120a1866bf5daad6ae0dce74907a513ff55b21fc0a52ba0ce7d650cc485
5757

5858
LABEL name="Snyk Controller" \
5959
maintainer="support@snyk.io" \

0 commit comments

Comments
 (0)