Skip to content

feat(gha/allenporter/flux-local): update 8.1.0 ➼ 8.4.0 - #5412

Open
tinfoild[bot] wants to merge 1 commit into
mainfrom
renovate/allenporter-flux-local-8.x
Open

tinfoild[bot] wants to merge 1 commit into
mainfrom
renovate/allenporter-flux-local-8.x

Conversation

@tinfoild

@tinfoild tinfoild Bot commented Apr 13, 2026 •

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Type Update Change OpenSSF
allenporter/flux-local action minor 8.1.0 → 8.4.0 OpenSSF Scorecard

Warning

Some dependencies could not be looked up. Check the Dependency Dashboard for more information.


Release Notes

allenporter/flux-local (allenporter/flux-local)

v8.4.0

Compare Source

What's Changed

Full Changelog: allenporter/flux-local@8.3.0...8.4.0

v8.3.0

Compare Source

What's Changed

New Contributors

Full Changelog: allenporter/flux-local@8.2.0...8.3.0

v8.2.0

Compare Source

What's Changed

New Contributors

Full Changelog: allenporter/flux-local@8.1.0...8.2.0


Configuration

📅 Schedule: (in timezone Asia/Singapore)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate.

@cloudflare-workers-and-pages

cloudflare-workers-and-pages Bot commented Apr 13, 2026 •

Copy link
Copy Markdown

Deploying jjgadgets-biohazard with  Cloudflare Pages  Cloudflare Pages

Latest commit: 6fc53f8
Status:🚫  Build failed.

View logs

@tinfoild

tinfoild Bot commented Apr 13, 2026

Copy link
Copy Markdown
Contributor Author

kube/helmrelease/out00

@tinfoild
tinfoild Bot force-pushed the renovate/allenporter-flux-local-8.x branch 3 times, most recently from 0efa569 to 8c59d0c Compare April 16, 2026 17:40
@tinfoild

tinfoild Bot commented Apr 16, 2026

Copy link
Copy Markdown
Contributor Author

kube/kustomization/out00

@tinfoild
tinfoild Bot force-pushed the renovate/allenporter-flux-local-8.x branch 4 times, most recently from 1fad919 to e765553 Compare April 21, 2026 12:33
@tinfoild
tinfoild Bot force-pushed the renovate/allenporter-flux-local-8.x branch 2 times, most recently from 3ce4387 to 50dcc1c Compare April 27, 2026 11:44
@tinfoild
tinfoild Bot force-pushed the renovate/allenporter-flux-local-8.x branch from 50dcc1c to ef57089 Compare May 6, 2026 09:53
@tinfoild
tinfoild Bot force-pushed the renovate/allenporter-flux-local-8.x branch from ef57089 to 409d715 Compare May 13, 2026 17:46
@tinfoild
tinfoild Bot force-pushed the renovate/allenporter-flux-local-8.x branch 2 times, most recently from 4564d41 to 2d4e046 Compare May 22, 2026 19:37
@tinfoild
tinfoild Bot force-pushed the renovate/allenporter-flux-local-8.x branch from 2d4e046 to 6b55bde Compare June 5, 2026 09:21
@tinfoild
tinfoild Bot force-pushed the renovate/allenporter-flux-local-8.x branch 3 times, most recently from 006e4b8 to 76598d9 Compare June 18, 2026 02:03
@tinfoild tinfoild Bot changed the title feat(gha/allenporter/flux-local): update 8.1.0 ➼ 8.2.0 feat(gha/allenporter/flux-local): update 8.1.0 ➼ 8.3.0 Jun 18, 2026
@tinfoild
tinfoild Bot force-pushed the renovate/allenporter-flux-local-8.x branch from 76598d9 to 9dad6da Compare July 2, 2026 15:23
@tinfoild
tinfoild Bot force-pushed the renovate/allenporter-flux-local-8.x branch from 9dad6da to 6604514 Compare July 9, 2026 17:30
@tinfoild tinfoild Bot changed the title feat(gha/allenporter/flux-local): update 8.1.0 ➼ 8.3.0 feat(gha/allenporter/flux-local): update 8.1.0 ➼ 8.4.0 Jul 9, 2026
@tinfoild
tinfoild Bot force-pushed the renovate/allenporter-flux-local-8.x branch 2 times, most recently from 842d19f to 693b107 Compare July 22, 2026 08:35
@ciel-shieru

ciel-shieru commented Jul 24, 2026 •

Copy link
Copy Markdown
Contributor

SECURITY VULNERABILITIES FOUND BY CIEL

📅 Scan date: 2026-07-24 02:53 UTC
🤖 Scanner: Ciel Security Scanner
🔗 PR: #5412 — feat(gha/allenporter/flux-local): update 8.1.0 ➼ 8.4.0
📦 Packages checked: 1
🔍 Sources: NVD, OSV.dev, GHSA, GHSL, CISA KEV, FortiGuard, CVE.org, Changelog
⚠️ Vulnerabilities found: 2 (transitive via GitPython)


Severity Summary

Severity Count
CRITICAL 1
HIGH 1
MEDIUM / MODERATE 0
LOW 0
UNKNOWN / NEEDS VERIFICATION 0
Total 2

Results

Package: allenporter/flux-local

  • Ecosystem: GitHub Actions (Python)
  • Old version: 8.1.0 — VULNERABLE (2 CVEs via GitPython 3.1.45)
  • New version: 8.4.0 — CLEAN (requires GitPython >= 3.1.47, pins 3.1.50)

Vulnerabilities in version 8.1.0

  1. CVE-2026-42215 / GHSA-rpm5-65cw-6hj4 — Severity: CRITICAL (CVSS 9.1)

    • Description: GitPython command injection via Git options bypass — Python kwargs bypass the unsafe-option blocklist, enabling RCE.
    • Affected versions: GitPython >= 3.1.30, < 3.1.47
    • Fixed in: GitPython 3.1.47
    • Sources: OSV.dev, GHSA
    • Evidence: https://nvd.nist.gov/vuln/detail/CVE-2026-42215 | GHSA-rpm5-65cw-6hj4
    • Status: ✅ Fixed in newer versions
  2. CVE-2026-42284 / GHSA-x2qx-6953-8485 — Severity: HIGH (CVSS 8.1)

    • Description: GitPython unsafe option check validates multi_options before shlex.split transformation, enabling command injection.
    • Affected versions: GitPython >= 0, < 3.1.47
    • Fixed in: GitPython 3.1.47
    • Sources: OSV.dev, GHSA
    • Evidence: https://nvd.nist.gov/vuln/detail/CVE-2026-42284 | GHSA-x2qx-6953-8485
    • Status: ✅ Fixed in newer versions

Vulnerabilities in version 8.4.0

No direct vulnerabilities found. Requires GitPython >= 3.1.47 (pins 3.1.50), which addresses both CVEs above. Note: GitPython 3.1.50 still has some unfixed advisory-level issues (GHSA-2f96-g7mh-g2hx, GHSA-956x-8gvw-wg5v, GHSA-rwj8-pgh3-r573) that are outside flux-local's control and require future GitPython updates to resolve.

Changelog Security Highlights (8.1.0 → 8.4.0)


Non-applicable findings (verified and excluded)

Finding Severity Reason not applicable
CVE-2026-44243 / GHSA-7545-fcxq-7j24 HIGH Fixed in GitPython 3.1.48; flux-local 8.4.0 pins 3.1.50
CVE-2026-44244 / GHSA-v87r-6q3f-2j67 HIGH Fixed in GitPython 3.1.49; flux-local 8.4.0 pins 3.1.50
GHSA-mv93-w799-cj2w HIGH Fixed in GitPython 3.1.50; flux-local 8.4.0 pins 3.1.50

Recommendations

  • MERGE PRIORITY: CRITICAL — The old version (8.1.0) depends on GitPython 3.1.45, which exposes 1 CRITICAL (CVE-2026-42215, CVSS 9.1) and 1 HIGH (CVE-2026-42284, CVSS 8.1) vulnerability. Version 8.4.0 bumps the dependency requirement to GitPython >= 3.1.47 (pins 3.1.50), remediating both. No new vulnerabilities introduced by this update.
  • Merge this PR promptly to close the active exposure to GitPython command injection CVEs.

⚠️ This comment was updated by an automated security scanner (Ciel).
To re-scan, trigger the renovate-security-scanner skill.

@tinfoild
tinfoild Bot force-pushed the renovate/allenporter-flux-local-8.x branch from 693b107 to 6fc53f8 Compare July 27, 2026 13:49
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant