Skip to content

Conversation

@Ankush-Pathak
Copy link
Member

Remediating GHSA-4qg8-fj49-pxjh requires upgrading github.com/sigstore/timestamp-authority from v1.2.9 to v2.0.3. github.com/sigstore/timestamp-authority is a transitive dependency and attempting to upgrade results in build failures.

Remediating GHSA-f83f-xpx7-ffpw requires upgrading github.com/sigstore/fulcio to 1.8.3. github.com/sigstore/fulcio is a transitive dependency and attempting to upgrade results in build failures. See failing upstream PR: tektoncd/cli#2675

Signed-off-by: Ankush Pathak [email protected]

@Ankush-Pathak Ankush-Pathak marked this pull request as ready for review December 15, 2025 14:23
@Ankush-Pathak Ankush-Pathak requested a review from a team December 15, 2025 14:23
@Ankush-Pathak Ankush-Pathak added this pull request to the merge queue Dec 15, 2025
Merged via the queue into wolfi-dev:main with commit c86df0f Dec 15, 2025
4 checks passed
@Ankush-Pathak Ankush-Pathak deleted the tkn/GHSA-4qg8-fj49-pxjh/GHSA-f83f-xpx7-ffpw branch December 15, 2025 14:56
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants