Skip to content

Conversation

@octo-sts
Copy link
Contributor

@octo-sts octo-sts bot commented Jan 2, 2026

spark-4.1/4.1.0-r0: fix GHSA-c476-j253-5rgq

Advisory data: https://github.com/wolfi-dev/advisories/blob/main/spark-4.1.advisories.yaml


"Breadcrumbs" for this automated service

Inspected git repositories: https://github.com/apache/spark@v4.1.0

@octo-sts octo-sts bot added automated pr request-cve-remediation maven/pombump GHSA-c476-j253-5rgq p:spark-4.1 bincapz/blocking Bincapz (aka malcontent) scan results detected CRITICALs on the packages. labels Jan 2, 2026
@antitree antitree added the malcontent/reviewed The malcontent findings in this PR have been manually reviewed by security. label Jan 2, 2026
@octo-sts
Copy link
Contributor Author

octo-sts bot commented Jan 7, 2026

This vulnerability remediation is stale and no longer needed. 👋

Advisory CGA-rhx6-339v-m2r5 has the latest event type of "pending-upstream-fix": https://github.com/wolfi-dev/advisories/blob/main/spark-4.1.advisories.yaml

ID:      CGA-rhx6-339v-m2r5
Package: spark-4.1
Aliases: CVE-2024-29869 GHSA-c476-j253-5rgq
Events:
  - "scan/v1" at 2026-01-02 09:00:21 UTC
  - "pending-upstream-fix" at 2026-01-06 19:00:00 UTC

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

automated pr bincapz/blocking Bincapz (aka malcontent) scan results detected CRITICALs on the packages. GHSA-c476-j253-5rgq malcontent/reviewed The malcontent findings in this PR have been manually reviewed by security. maven/pombump p:spark-4.1 request-cve-remediation service:cve-pr-closer

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants