Skip to content

[GHSA-wjxp-xrpv-xpff] Add multi-branch patch ranges for Tekton Pipelines#7596

Open
waveywaves wants to merge 1 commit intogithub:waveywaves/advisory-improvement-7596from
waveywaves:fix-GHSA-wjxp-xrpv-xpff-multi-branch-patches
Open

[GHSA-wjxp-xrpv-xpff] Add multi-branch patch ranges for Tekton Pipelines#7596
waveywaves wants to merge 1 commit intogithub:waveywaves/advisory-improvement-7596from
waveywaves:fix-GHSA-wjxp-xrpv-xpff-multi-branch-patches

Conversation

@waveywaves
Copy link
Copy Markdown

Summary

GHSA-wjxp-xrpv-xpff (CVE-2026-40161): Git resolver API mode leaks system-configured API token

This advisory was patched across five maintained Tekton Pipelines LTS branches on April 21, 2026, but the OSV entry collapses the fix into a single range. Users on patched LTS releases are incorrectly flagged as vulnerable by dependency tooling.

Changes

Replaced the single OSV range with five per-branch ranges so each patched version is recognized as fixed:

  • v1.0.2 (release-v1.0.x)
  • v1.3.4 (release-v1.3.x)
  • v1.6.2 (release-v1.6.x)
  • v1.9.3 (release-v1.9.x)
  • v1.11.1 (release-v1.11.x)

Also updated modified timestamp and last_known_affected_version_range to align with the revised ranges.

Source

Repository advisory: GHSA-wjxp-xrpv-xpff

Copilot AI review requested due to automatic review settings May 6, 2026 14:47
@github-actions github-actions Bot changed the base branch from main to waveywaves/advisory-improvement-7596 May 6, 2026 14:48
Git resolver API mode leaks system-configured API token to user-controlled serverURL (CVE-2026-40161) was patched across five maintained LTS branches on
April 21, 2026, but the OSV entry here collapses the fix into a single
range. Users on patched LTS releases (v1.0.2, v1.3.4, v1.6.2, v1.9.3)
are incorrectly flagged as vulnerable by dependency tooling.

Updated to use one OSV range per branch so each patched version is
recognized as fixed: v1.0.2, v1.3.4, v1.6.2, v1.9.3, v1.11.1.

Source: GHSA-wjxp-xrpv-xpff
@waveywaves waveywaves force-pushed the fix-GHSA-wjxp-xrpv-xpff-multi-branch-patches branch from 6da79ae to 0fcdda1 Compare May 6, 2026 17:22
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant