This release includes 1 security fix for security teams reviewing exposed deployments.
Published 14d
Build & Package
✓ No known CVEs patched
This release patches 1 known CVE
Topics
containers
docker
Affected surfaces
auth
deps
Summary
AI summaryMinor fixes and improvements.
Full changelog
Changelog
- 34cdf14533a0f0d7874cce7a7e514f937ffd7386 build(deps): bump chainguard.dev/sdk from 0.1.94 to 0.1.112 (#2325)
- 5578e9caa57ae3438f0459bd46a49cae299f8c4f build(deps): bump docker/setup-qemu-action from 4.1.0 to 4.2.0 (#2319)
- 370ef5e4e41bf860769b4f082fb14b43103d4fe1 build(deps): bump github/codeql-action/analyze from 4.36.2 to 4.36.3 (#2317)
- 36cc8eacde720f30a56c586f028dc78836ca483e build(deps): bump github/codeql-action/init from 4.36.2 to 4.36.3 (#2318)
- e800257f56ba6767d92642423c9c3e3aff724411 build(deps): bump golang.org/x/sync from 0.21.0 to 0.22.0 (#2321)
- 5c03febf8de4265114b5c9475a7f9df223d37867 build(deps): bump golang.org/x/sys from 0.46.0 to 0.47.0 (#2320)
- 5683ec1022abfc1a4c85756fcefdce22941fd11e build(deps): bump google.golang.org/api from 0.286.0 to 0.287.0 (#2316)
- f1f87b87c80349faff39122409071c7f6315bbae build(deps): bump step-security/harden-runner from 2.19.4 to 2.20.0 (#2324)
- a18ce4b6be29d806a26e15d3f633bb15a01eacfb fix(accounts): add missing /etc/shadow entries for apko-created users (#2323)
Security Fixes
- Add missing /etc/shadow entries for apko-created users (fix(accounts))
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
Related context
Related tools
Beta — feedback welcome: [email protected]