Skip to content

Improve Release Changelog Generation #904

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Merged
merged 1 commit into from
Mar 14, 2025
Merged

Improve Release Changelog Generation #904

merged 1 commit into from
Mar 14, 2025

Conversation

bjoernricks
Copy link
Contributor

What

Improve Release Changelog Generation

Why

Add a new CI workflow for showing the latest changelog independent of a release. Use git-cliff to generate a more flexible and improved release changelog.

References

https://jira.greenbone.net/browse/GEA-984

Add a new CI workflow for showing the latest changelog independent of a
release. Use git-cliff to generate a more flexible and improved release
changelog.
@bjoernricks bjoernricks requested review from a team as code owners March 14, 2025 07:14
@bjoernricks bjoernricks enabled auto-merge (rebase) March 14, 2025 07:14
Copy link

Dependency Review

The following issues were found:
  • ✅ 0 vulnerable package(s)
  • ✅ 0 package(s) with incompatible licenses
  • ✅ 0 package(s) with invalid SPDX license definitions
  • ⚠️ 3 package(s) with unknown licenses.
See the Details below.

Snapshot Warnings

⚠️: No snapshots were found for the head SHA 98ba05d.
Ensure that dependencies are being submitted on PR branches and consider enabling retry-on-snapshot-warnings. See the documentation for more information and troubleshooting advice.

License Issues

.github/workflows/changelog.yml

PackageVersionLicenseIssue Type
greenbone/actions/uv3.*.*NullUnknown License

.github/workflows/release.yml

PackageVersionLicenseIssue Type
greenbone/actions/release-version3.*.*NullUnknown License
greenbone/actions/uv3.*.*NullUnknown License
Allowed Licenses: 0BSD, AGPL-3.0-or-later, Apache-2.0, BlueOak-1.0.0, BSD-2-Clause, BSD-3-Clause-Clear, BSD-3-Clause, BSL-1.0, CAL-1.0, CC-BY-3.0, CC-BY-4.0, CC-BY-SA-4.0, CC0-1.0, EPL-2.0, GPL-2.0-only, GPL-2.0-or-later, GPL-2.0, GPL-3.0-or-later, ISC, LGPL-2.0-only, LGPL-2.0-or-later, LGPL-2.1-only, LGPL-2.1-or-later, LGPL-2.1, LGPL-3.0-only, LGPL-3.0, LGPL-3.0-or-later, MIT, MIT-CMU, MPL-1.1, MPL-2.0, OFL-1.1, PSF-2.0, Python-2.0, Python-2.0.1, Unicode-DFS-2016, Unlicense, Zlib, ZPL-2.1

OpenSSF Scorecard

PackageVersionScoreDetails
actions/actions/checkout 4.*.* 🟢 6
Details
CheckScoreReason
Code-Review🟢 10all changesets reviewed
Binary-Artifacts🟢 10no binaries found in the repo
Maintained⚠️ 22 commit(s) and 1 issue activity found in the last 90 days -- score normalized to 2
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
Token-Permissions⚠️ 0detected GitHub workflow tokens with excessive permissions
License🟢 10license file detected
Fuzzing⚠️ 0project is not fuzzed
Signed-Releases⚠️ -1no releases found
Pinned-Dependencies🟢 3dependency not pinned by hash detected -- score normalized to 3
Branch-Protection⚠️ -1internal error: error during branchesHandler.setup: internal error: githubv4.Query: Resource not accessible by integration
Security-Policy🟢 9security policy file detected
Packaging🟢 10packaging workflow detected
SAST🟢 9SAST tool detected but not run on all commits
Vulnerabilities🟢 37 existing vulnerabilities detected
actions/greenbone/actions/uv 3.*.* UnknownUnknown
actions/actions/checkout 4.*.* 🟢 6
Details
CheckScoreReason
Code-Review🟢 10all changesets reviewed
Binary-Artifacts🟢 10no binaries found in the repo
Maintained⚠️ 22 commit(s) and 1 issue activity found in the last 90 days -- score normalized to 2
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
Token-Permissions⚠️ 0detected GitHub workflow tokens with excessive permissions
License🟢 10license file detected
Fuzzing⚠️ 0project is not fuzzed
Signed-Releases⚠️ -1no releases found
Pinned-Dependencies🟢 3dependency not pinned by hash detected -- score normalized to 3
Branch-Protection⚠️ -1internal error: error during branchesHandler.setup: internal error: githubv4.Query: Resource not accessible by integration
Security-Policy🟢 9security policy file detected
Packaging🟢 10packaging workflow detected
SAST🟢 9SAST tool detected but not run on all commits
Vulnerabilities🟢 37 existing vulnerabilities detected
actions/greenbone/actions/release-version 3.*.* UnknownUnknown
actions/greenbone/actions/uv 3.*.* UnknownUnknown

Scanned Files

  • .github/workflows/changelog.yml
  • .github/workflows/release.yml

Copy link

github-actions bot commented Mar 14, 2025

🔍 Vulnerabilities of harbor-os.greenbone.net/community/gvm-libs:904-merge-amd64

📦 Image Reference harbor-os.greenbone.net/community/gvm-libs:904-merge-amd64
digestsha256:d6df6aa8735f720115a89b0e1f8701ba6f0fab7175ea7bdb2a8e2a709a00db04
vulnerabilitiescritical: 0 high: 4 medium: 4 low: 13 unspecified: 1
size69 MB
packages201
📦 Base Image debian:testing-20250224-slim
also known as
  • testing-slim
digestsha256:dd44ac7e9b6d7271b382c9bf5bce34920ecb1c3f2ec09426137a4e72de79fd11
vulnerabilitiescritical: 0 high: 0 medium: 1 low: 6
critical: 0 high: 4 medium: 2 low: 2 libxml2 2.12.7+dfsg+really2.9.14-0.2+b2 (deb)

pkg:deb/debian/[email protected]%2Bdfsg%2Breally2.9.14-0.2%2Bb2?os_distro=trixie&os_name=debian&os_version=unstable

high : CVE--2022--49043

Affected range>=2.12.7+dfsg+really2.9.14-0.2
Fixed versionNot Fixed
EPSS Score0.04%
EPSS Percentile12th percentile
Description

xmlXIncludeAddNode in xinclude.c in libxml2 before 2.11.0 has a use-after-free.


[experimental] - libxml2 2.12.3+dfsg-0exp1

high : CVE--2025--24928

Affected range>=2.12.7+dfsg+really2.9.14-0.2
Fixed versionNot Fixed
EPSS Score0.04%
EPSS Percentile12th percentile
Description

libxml2 before 2.12.10 and 2.13.x before 2.13.6 has a stack-based buffer overflow in xmlSnprintfElements in valid.c. To exploit this, DTD validation must occur for an untrusted document or untrusted DTD. NOTE: this is similar to CVE-2017-9047.


high : CVE--2024--56171

Affected range>=2.12.7+dfsg+really2.9.14-0.2
Fixed versionNot Fixed
EPSS Score0.04%
EPSS Percentile12th percentile
Description

libxml2 before 2.12.10 and 2.13.x before 2.13.6 has a use-after-free in xmlSchemaIDCFillNodeTables and xmlSchemaBubbleIDCNodeTables in xmlschemas.c. To exploit this, a crafted XML document must be validated against an XML schema with certain identity constraints, or a crafted XML schema must be used.


high : CVE--2024--25062

Affected range>=2.12.7+dfsg+really2.9.14-0.2
Fixed versionNot Fixed
EPSS Score0.10%
EPSS Percentile43rd percentile
Description

An issue was discovered in libxml2 before 2.11.7 and 2.12.x before 2.12.5. When using the XML Reader interface with DTD validation and XInclude expansion enabled, processing crafted XML documents can lead to an xmlValidatePopElement use-after-free.


[experimental] - libxml2 2.12.5+dfsg-0exp1

medium : CVE--2023--45322

Affected range>=2.12.7+dfsg+really2.9.14-0.2
Fixed versionNot Fixed
EPSS Score0.08%
EPSS Percentile37th percentile
Description

libxml2 through 2.11.5 has a use-after-free that can only occur after a certain memory allocation fails. This occurs in xmlUnlinkNode in tree.c. NOTE: the vendor's position is "I don't think these issues are critical enough to warrant a CVE ID ... because an attacker typically can't control when memory allocations fail."


[experimental] - libxml2 2.12.3+dfsg-0exp1

medium : CVE--2023--39615

Affected range>=2.12.7+dfsg+really2.9.14-0.2
Fixed versionNot Fixed
EPSS Score0.07%
EPSS Percentile34th percentile
Description

Xmlsoft Libxml2 v2.11.0 was discovered to contain an out-of-bounds read via the xmlSAX2StartElement() function at /libxml2/SAX2.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via supplying a crafted XML file. NOTE: the vendor's position is that the product does not support the legacy SAX1 interface with custom callbacks; there is a crash even without crafted input.


[experimental] - libxml2 2.12.3+dfsg-0exp1

low : CVE--2025--27113

Affected range>=2.12.7+dfsg+really2.9.14-0.2
Fixed versionNot Fixed
EPSS Score0.05%
EPSS Percentile20th percentile
Description

libxml2 before 2.12.10 and 2.13.x before 2.13.6 has a NULL pointer dereference in xmlPatMatch in pattern.c.


low : CVE--2024--34459

Affected range>=2.12.7+dfsg+really2.9.14-0.2
Fixed versionNot Fixed
EPSS Score0.04%
EPSS Percentile13th percentile
Description

An issue was discovered in xmllint (from libxml2) before 2.11.8 and 2.12.x before 2.12.7. Formatting error messages with xmllint --htmlout can result in a buffer over-read in xmlHTMLPrintFileContext in xmllint.c.


critical: 0 high: 0 medium: 1 low: 1 libgcrypt20 1.11.0-7 (deb)

pkg:deb/debian/[email protected]?os_distro=trixie&os_name=debian&os_version=unstable

medium : CVE--2024--2236

Affected range>=1.11.0-7
Fixed versionNot Fixed
EPSS Score0.04%
EPSS Percentile18th percentile
Description

A timing-based side-channel flaw was found in libgcrypt's RSA implementation. This issue may allow a remote attacker to initiate a Bleichenbacher-style attack, which can lead to the decryption of RSA ciphertexts.


low : CVE--2018--6829

Affected range>=1.11.0-7
Fixed versionNot Fixed
EPSS Score0.33%
EPSS Percentile71st percentile
Description

cipher/elgamal.c in Libgcrypt through 1.8.2, when used to encrypt messages directly, improperly encodes plaintexts, which allows attackers to obtain sensitive information by reading ciphertext data (i.e., it does not have semantic security in face of a ciphertext-only attack). The Decisional Diffie-Hellman (DDH) assumption does not hold for Libgcrypt's ElGamal implementation.


critical: 0 high: 0 medium: 1 low: 0 libcap2 1:2.66-5+b1 (deb)

pkg:deb/debian/libcap2@1:2.66-5%2Bb1?os_distro=trixie&os_name=debian&os_version=unstable

medium : CVE--2025--1390

Affected range<1:2.73-4
Fixed version1:2.73-4
EPSS Score0.04%
EPSS Percentile12th percentile
Description

The PAM module pam_cap.so of libcap configuration supports group names starting with “@”, during actual parsing, configurations not starting with “@” are incorrectly recognized as group names. This may result in nonintended users being granted an inherited capability set, potentially leading to security risks. Attackers can exploit this vulnerability to achieve local privilege escalation on systems where /etc/security/capability.conf is used to configure user inherited privileges by constructing specific usernames.


critical: 0 high: 0 medium: 0 low: 2 coreutils 9.5-1+b1 (deb)

pkg:deb/debian/[email protected]%2Bb1?os_distro=trixie&os_name=debian&os_version=unstable

low : CVE--2017--18018

Affected range>=9.5-1
Fixed versionNot Fixed
EPSS Score0.04%
EPSS Percentile5th percentile
Description

In GNU Coreutils through 8.29, chown-core.c in chown and chgrp does not prevent replacement of a plain file with a symlink during use of the POSIX "-R -L" options, which allows local users to modify the ownership of arbitrary files by leveraging a race condition.


low : CVE--2016--2781

Affected range>=9.5-1
Fixed versionNot Fixed
EPSS Score0.04%
EPSS Percentile5th percentile
Description

chroot in GNU coreutils, when used with --userspec, allows local users to escape to the parent session via a crafted TIOCSTI ioctl call, which pushes characters to the terminal's input buffer.


critical: 0 high: 0 medium: 0 low: 1 util-linux 2.40.4-5 (deb)

pkg:deb/debian/[email protected]?os_distro=trixie&os_name=debian&os_version=unstable

low : CVE--2022--0563

Affected range>=2.40.4-5
Fixed versionNot Fixed
EPSS Score0.05%
EPSS Percentile20th percentile
Description

A flaw was found in the util-linux chfn and chsh utilities when compiled with Readline support. The Readline library uses an "INPUTRC" environment variable to get a path to the library config file. When the library cannot parse the specified file, it prints an error message containing data from the file. This flaw allows an unprivileged user to read root-owned files, potentially leading to privilege escalation. This flaw affects util-linux versions prior to 2.37.4.


critical: 0 high: 0 medium: 0 low: 1 sqlite3 3.46.1-2 (deb)

pkg:deb/debian/[email protected]?os_distro=trixie&os_name=debian&os_version=unstable

low : CVE--2021--45346

Affected range>=3.46.1-2
Fixed versionNot Fixed
EPSS Score0.28%
EPSS Percentile69th percentile
Description

A Memory Leak vulnerability exists in SQLite Project SQLite3 3.35.1 and 3.37.0 via maliciously crafted SQL Queries (made via editing the Database File), it is possible to query a record, and leak subsequent bytes of memory that extend beyond the record, which could let a malicious user obtain sensitive information. NOTE: The developer disputes this as a vulnerability stating that If you give SQLite a corrupted database file and submit a query against the database, it might read parts of the database that you did not intend or expect.


critical: 0 high: 0 medium: 0 low: 1 gnutls28 3.8.9-2 (deb)

pkg:deb/debian/[email protected]?os_distro=trixie&os_name=debian&os_version=unstable

low : CVE--2011--3389

Affected range>=3.8.9-2
Fixed versionNot Fixed
EPSS Score1.43%
EPSS Percentile87th percentile
Description

The SSL protocol, as used in certain configurations in Microsoft Windows and Microsoft Internet Explorer, Mozilla Firefox, Google Chrome, Opera, and other products, encrypts data by using CBC mode with chained initialization vectors, which allows man-in-the-middle attackers to obtain plaintext HTTP headers via a blockwise chosen-boundary attack (BCBA) on an HTTPS session, in conjunction with JavaScript code that uses (1) the HTML5 WebSocket API, (2) the Java URLConnection API, or (3) the Silverlight WebClient API, aka a "BEAST" attack.


critical: 0 high: 0 medium: 0 low: 1 openssl 3.4.1-1 (deb)

pkg:deb/debian/[email protected]?os_distro=trixie&os_name=debian&os_version=unstable

low : CVE--2010--0928

Affected range>=3.2.2-1
Fixed versionNot Fixed
EPSS Score0.07%
EPSS Percentile32nd percentile
Description

OpenSSL 0.9.8i on the Gaisler Research LEON3 SoC on the Xilinx Virtex-II Pro FPGA uses a Fixed Width Exponentiation (FWE) algorithm for certain signature calculations, and does not verify the signature before providing it to a caller, which makes it easier for physically proximate attackers to determine the private key via a modified supply voltage for the microprocessor, related to a "fault-based attack."


http://www.eecs.umich.edu/~valeria/research/publications/DATE10RSA.pdf
openssl/openssl#24540
Fault injection based attacks are not within OpenSSLs threat model according
to the security policy: https://www.openssl.org/policies/general/security-policy.html

critical: 0 high: 0 medium: 0 low: 1 pam 1.7.0-3 (deb)

pkg:deb/debian/[email protected]?os_distro=trixie&os_name=debian&os_version=unstable

low : CVE--2024--10963

Affected range>=1.7.0-3
Fixed versionNot Fixed
EPSS Score0.04%
EPSS Percentile16th percentile
Description

A flaw was found in pam_access, where certain rules in its configuration file are mistakenly treated as hostnames. This vulnerability allows attackers to trick the system by pretending to be a trusted hostname, gaining unauthorized access. This issue poses a risk for systems that rely on this feature to control who can access certain services or terminals.


critical: 0 high: 0 medium: 0 low: 1 perl 5.40.1-2 (deb)

pkg:deb/debian/[email protected]?os_distro=trixie&os_name=debian&os_version=unstable

low : CVE--2011--4116

Affected range>=5.40.1-2
Fixed versionNot Fixed
EPSS Score0.14%
EPSS Percentile52nd percentile
Description

_is_safe in the File::Temp module for Perl does not properly handle symlinks.


critical: 0 high: 0 medium: 0 low: 1 tar 1.35+dfsg-3.1 (deb)

pkg:deb/debian/[email protected]%2Bdfsg-3.1?os_distro=trixie&os_name=debian&os_version=unstable

low : CVE--2005--2541

Affected range>=1.35+dfsg-3.1
Fixed versionNot Fixed
EPSS Score0.69%
EPSS Percentile80th percentile
Description

Tar 1.15.1 does not properly warn the user when extracting setuid or setgid files, which may allow local users or remote attackers to gain privileges.


This is intended behaviour, after all tar is an archiving tool and you
need to give -p as a command line flag

critical: 0 high: 0 medium: 0 low: 1 glib2.0 2.84.0-1 (deb)

pkg:deb/debian/[email protected]?os_distro=trixie&os_name=debian&os_version=unstable

low : CVE--2012--0039

Affected range>=2.84.0-1
Fixed versionNot Fixed
EPSS Score0.16%
EPSS Percentile53rd percentile
Description

GLib 2.31.8 and earlier, when the g_str_hash function is used, computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted input to an application that maintains a hash table. NOTE: this issue may be disputed by the vendor; the existence of the g_str_hash function is not a vulnerability in the library, because callers of g_hash_table_new and g_hash_table_new_full can specify an arbitrary hash function that is appropriate for the application.


critical: 0 high: 0 medium: 0 low: 0 unspecified: 1krb5 1.21.3-4 (deb)

pkg:deb/debian/[email protected]?os_distro=trixie&os_name=debian&os_version=unstable

unspecified : CVE--2025--24528

Affected range<1.21.3-5
Fixed version1.21.3-5
Description

@bjoernricks bjoernricks merged commit 638d0ae into main Mar 14, 2025
25 checks passed
@bjoernricks bjoernricks deleted the release-workflow branch March 14, 2025 07:55
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants