Skip to content

AST-165915 - Bump containers-syft-packages-extractor to v1.0.27 - #54

Merged
cx-dmitri-rivin merged 1 commit into
mainfrom
bug/AST-165915-002
Sep 8, 2026
Merged

cx-dmitri-rivin merged 1 commit into
mainfrom
bug/AST-165915-002

Conversation

@cx-dmitri-rivin

@cx-dmitri-rivin cx-dmitri-rivin commented Sep 8, 2026

Copy link
Copy Markdown
Contributor

Summary

  • Update github.com/Checkmarx/containers-syft-packages-extractor dependency from v1.0.26 to v1.0.27

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
@cx-dmitri-rivin cx-dmitri-rivin changed the title Bump containers-syft-packages-extractor to v1.0.27 AST-165915 - Bump containers-syft-packages-extractor to v1.0.27 Sep 8, 2026
@cx-shaked-karta

Copy link
Copy Markdown
Contributor

Logo
Checkmarx One – Scan Summary & Detailsd84c58e7-ad72-43ba-9a20-238c58648f41


New Issues (1)

High: 1

Checkmarx found the following issues in this Pull Request

# Severity Issue Source File / Package Checkmarx Insight
1 HIGH CVE-2026-84304 Go-google.golang.org/grpc-v1.79.3
detailsRecommended version: v1.83.1
Description: gRPC-Go is the Go language implementation of gRPC. Prior to 1.83.1, "internal/transport/transport.go" stores each fragmented HTTP/2 DATA frame as a...
Attack Vector: NETWORK
Attack Complexity: LOW
Vulnerable Package

Use @Checkmarx to interact with Checkmarx PR Assistant.
Examples:
@Checkmarx how are you able to help me?
@Checkmarx rescan this PR

@cx-dmitri-rivin
cx-dmitri-rivin merged commit c638609 into main Sep 8, 2026
7 of 10 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants