-
Notifications
You must be signed in to change notification settings - Fork 116
CVE(s) found in v0.21.7 #1626
Copy link
Copy link
Open
Labels
Description
Latest lifecycle release v0.21.7 triggered CVE(s) from Grype. For further details, see: https://github.com/buildpacks/lifecycle/actions/runs/23725950205 json: {
"id": "GHSA-x744-4wpc-v9h2",
"severity": "High",
"description": "Moby has AuthZ plugin bypass when provided oversized request bodies"
}
{
"id": "GHSA-pxq6-2prw-chj9",
"severity": "Medium",
"description": "Moby has an Off-by-one error in its plugin privilege validation"
}
Reactions are currently unavailable