Skip to content

downgrade github.com/cyphar/filepath-securejoin to v0.5.1#242

Merged
rhatdan merged 1 commit intoopencontainers:mainfrom
Luap99:securejoin
Nov 14, 2025
Merged

downgrade github.com/cyphar/filepath-securejoin to v0.5.1#242
rhatdan merged 1 commit intoopencontainers:mainfrom
Luap99:securejoin

Conversation

@Luap99
Copy link
Copy Markdown
Contributor

@Luap99 Luap99 commented Nov 14, 2025

This library doesn't need to use v6 and in order to fix the CVe fixed here it is not great to force all users to update securejoin to v6 as that update did some breaking changes.

see #241

This library doesn't need to use v6 and in order to fix the CVe fixed
here it is not great to force all users to update securejoin to v6 as
that update did some breaking changes.

see opencontainers#241

Signed-off-by: Paul Holzinger <[email protected]>
@Luap99
Copy link
Copy Markdown
Contributor Author

Luap99 commented Nov 14, 2025

As mentioned in the issue #241 I am not sure if it makes sense to downgrade on main, I think it would be easier if someone could create a 1.12 branch based of main and then I target that branch and then release a v1.12.1

cc @cyphar @kolyshkin @rhatdan

@cyphar
Copy link
Copy Markdown
Member

cyphar commented Nov 14, 2025

I think downgrading on main is fine, since we don't use any of the features in v0.6.

@Luap99
Copy link
Copy Markdown
Contributor Author

Luap99 commented Nov 14, 2025

Ok in that case it is even simpler and we could release 1.13.1 here with his.

@cyphar
Copy link
Copy Markdown
Member

cyphar commented Nov 14, 2025

Oh, Dan added me to the reviewers list but I'm not officially a maintainer... Let me open a PR for that...

Copy link
Copy Markdown
Collaborator

@rhatdan rhatdan left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@rhatdan rhatdan merged commit 5647f06 into opencontainers:main Nov 14, 2025
17 checks passed
@Luap99 Luap99 deleted the securejoin branch November 14, 2025 16:08
@Luap99
Copy link
Copy Markdown
Contributor Author

Luap99 commented Nov 14, 2025

Thanks @cyphar and @rhatdan. Could one of you tag v1.13.1?

@cyphar
Copy link
Copy Markdown
Member

cyphar commented Nov 14, 2025

I guess since I have push rights, it's okay for me to do it -- https://github.com/opencontainers/selinux/releases/tag/v1.13.1.

kb2ma added a commit to balena-os/balena-engine that referenced this pull request Nov 15, 2025
Also update balena-containerd to v20.10.17-balena-runc-1.2.8 branch.
Also update selinux to v1.13.1 to get fixed post-embargo version. See
opencontainers/selinux#242 for details.

Mitigates CVE-2025-31133, CVE-2025-52565, and CVE-2025-52881.

Change-type: patch
Signed-off-by: Ken Bannister <[email protected]>
kb2ma added a commit to balena-os/balena-engine that referenced this pull request Nov 19, 2025
Also update balena-containerd to v20.10-balena-runc-1.2.8 branch.
Also update selinux to v1.13.1 to get fixed post-embargo version. See
opencontainers/selinux#242 for details.

Mitigates CVE-2025-31133, CVE-2025-52565, and CVE-2025-52881.

Change-type: patch
Signed-off-by: Ken Bannister <[email protected]>
kb2ma added a commit to balena-os/balena-engine that referenced this pull request Nov 26, 2025
Also update balena-containerd to v20.10-balena-runc-1.2.8 branch.
Also update selinux to v1.13.1 to get fixed post-embargo version. See
opencontainers/selinux#242 for details.

Mitigates CVE-2025-31133, CVE-2025-52565, and CVE-2025-52881.

Change-type: patch
Signed-off-by: Ken Bannister <[email protected]>
kb2ma added a commit to balena-os/balena-engine that referenced this pull request Dec 2, 2025
Also update balena-containerd to v20.10-balena-upstream-1.6.38 branch.
Also update selinux to v1.13.1 to get fixed post-embargo version. See
opencontainers/selinux#242 for details.

Mitigates CVE-2025-31133, CVE-2025-52565, and CVE-2025-52881.

Change-type: patch
Signed-off-by: Ken Bannister <[email protected]>
kb2ma added a commit to balena-os/balena-engine that referenced this pull request Dec 4, 2025
Also update balena-containerd to v20.10-balena-upstream-1.6.27 branch.
Also update selinux to v1.13.1 to get fixed post-embargo version. See
opencontainers/selinux#242 for details.

Mitigates CVE-2025-31133, CVE-2025-52565, and CVE-2025-52881.

Change-type: patch
Signed-off-by: Ken Bannister <[email protected]>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants