Skip to content
New issue

Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? # to your account

Bump archiver and stereoscope to address path traversal issues #2570

Merged
merged 1 commit into from
Jan 31, 2024

Conversation

wagoodman
Copy link
Contributor

@wagoodman wagoodman commented Jan 31, 2024

Pulls in fixes from:

To address various tar path traversal bugs, specifically when malicious tar files are passed to syft (e.g. syft ./path/to/my.tar).

Signed-off-by: Alex Goodman <wagoodman@users.noreply.github.com>
@wagoodman wagoodman marked this pull request as ready for review January 31, 2024 16:11
@wagoodman wagoodman requested a review from a team January 31, 2024 16:11
@wagoodman wagoodman added the security related to vulnerability remediation label Jan 31, 2024
@wagoodman wagoodman changed the title Bump archiver and stereoscope to address path traversal issue Bump archiver and stereoscope to address path traversal issues Jan 31, 2024
@wagoodman wagoodman merged commit bbe7fa1 into main Jan 31, 2024
11 checks passed
@wagoodman wagoodman deleted the fix-tar-path-traversal branch January 31, 2024 16:24
GijsCalis pushed a commit to GijsCalis/syft that referenced this pull request Feb 19, 2024
Signed-off-by: Alex Goodman <wagoodman@users.noreply.github.com>
# for free to join this conversation on GitHub. Already have an account? # to comment
Labels
security related to vulnerability remediation
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants