Skip to content

NO-ISSUE: Refresh RPM lockfiles [SECURITY]#1361

Open
red-hat-konflux[bot] wants to merge 1 commit intomasterfrom
konflux/mintmaker/master/rpm-lockfile-refresh-vulnerability
Open

NO-ISSUE: Refresh RPM lockfiles [SECURITY]#1361
red-hat-konflux[bot] wants to merge 1 commit intomasterfrom
konflux/mintmaker/master/rpm-lockfile-refresh-vulnerability

Conversation

@red-hat-konflux
Copy link
Copy Markdown
Contributor

@red-hat-konflux red-hat-konflux bot commented Mar 10, 2026

This PR contains the following updates:

Update Change
lockFileMaintenance All locks refreshed

🔧 This Pull Request updates lock files to use the latest dependency versions.


Configuration

📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

To execute skipped test pipelines write comment /ok-to-test.


Documentation

Find out how to configure dependency updates in MintMaker documentation or see all available configuration options in Renovate documentation.

@openshift-ci-robot openshift-ci-robot added the jira/valid-reference Indicates that this PR references a valid Jira ticket of any type. label Mar 10, 2026
@openshift-ci-robot
Copy link
Copy Markdown

@red-hat-konflux[bot]: This pull request explicitly references no jira issue.

Details

In response to this:

This PR contains the following updates:

File rpm-prefetching/rpms.in.yaml:

Package Change
python-unversioned-command 3.9.25-3.el9_7 -> 3.9.25-3.el9_7.1
python3 3.9.25-3.el9_7 -> 3.9.25-3.el9_7.1
python3-libs 3.9.25-3.el9_7 -> 3.9.25-3.el9_7.1

cpython: IMAP command injection in user-controlled commands

CVE-2025-15366

More information

Details

A flaw was found in the imaplib module in the Python standard library. The imaplib module does not reject control characters, such as newlines, in user-controlled input passed to IMAP commands. This issue allows an attacker to inject additional commands to be executed in the IMAP server.

Severity

Moderate

References


cpython: email header injection due to unquoted newlines

CVE-2026-1299

More information

Details

A flaw was found in the email module in the Python standard library. When serializing an email message, the BytesGenerator class fails to properly quote newline characters for email headers. This issue is exploitable when the LiteralHeader class is used as it does not respect email folding rules, allowing an attacker to inject email headers and potentially modify message recipients or the email body, and spoof sender information.

Severity

Moderate

References


cpython: POP3 command injection in user-controlled commands

CVE-2025-15367

More information

Details

A flaw was found in the poplib module in the Python standard library. The poplib module does not reject control characters, such as newlines, in user-controlled input passed to POP3 commands. This issue allows an attacker to inject additional commands to be executed in the POP3 server.

Severity

Moderate

References

🔧 This Pull Request updates lock files to use the latest dependency versions.


Configuration

📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

To execute skipped test pipelines write comment /ok-to-test.


Documentation

Find out how to configure dependency updates in MintMaker documentation or see all available configuration options in Renovate documentation.

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository.

@coderabbitai
Copy link
Copy Markdown

coderabbitai bot commented Mar 10, 2026

Note

Reviews paused

It looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the reviews.auto_review.auto_pause_after_reviewed_commits setting.

Use the following commands to manage reviews:

  • @coderabbitai resume to resume automatic reviews.
  • @coderabbitai review to trigger a single review.

Use the checkboxes below for quick actions:

  • ▶️ Resume reviews
  • 🔍 Trigger review

Walkthrough

Updated RPM lockfile rpm-prefetching/rpms.lock.yaml: bumped EVRs and sourcerpm versions and synchronized artifact metadata (url, size, sha256) for crun, python-unversioned-command, device-mapper/device-mapper-libs, openssh/openssh-clients, and python3/python3-libs across architectures.

Changes

Cohort / File(s) Summary
RPM lockfile
rpm-prefetching/rpms.lock.yaml
Per-architecture RPM metadata updates: EVR/sourcerpm bumps (e.g., crun 1.23.1-2.el9_7 → 1.26-1.el9_7; python-unversioned-command ...-3.el9_7...-3.el9_7.1; device-mapper/device-mapper-libs ...-2.el9_7.1...-2.el9_7.2; openssh/openssh-clients 8.7p1-47.el9_78.7p1-48.el9_7; python3/python3-libs ...-3.el9_7...-3.el9_7.1) and updated url, size, and sha256 fields for aarch64, x86_64, ppc64le, s390x, and noarch.

Estimated code review effort

🎯 2 (Simple) | ⏱️ ~10 minutes

🚥 Pre-merge checks | ✅ 2
✅ Passed checks (2 passed)
Check name Status Explanation
Title check ✅ Passed The title accurately describes the main change: refreshing RPM lockfiles for security purposes. It directly matches the changeset which updates multiple package versions to address security vulnerabilities.
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch konflux/mintmaker/master/rpm-lockfile-refresh-vulnerability

Comment @coderabbitai help to get the list of available commands and usage tips.

@openshift-ci openshift-ci bot added the size/L Denotes a PR that changes 100-499 lines, ignoring generated files. label Mar 10, 2026
@openshift-ci openshift-ci bot requested review from avishayt and linoyaslan March 10, 2026 16:27
@openshift-ci
Copy link
Copy Markdown

openshift-ci bot commented Mar 10, 2026

[APPROVALNOTIFIER] This PR is NOT APPROVED

This pull-request has been approved by: red-hat-konflux[bot]
Once this PR has been reviewed and has the lgtm label, please assign pastequo for approval. For more information see the Code Review Process.

The full list of commands accepted by this bot can be found here.

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@codecov
Copy link
Copy Markdown

codecov bot commented Mar 10, 2026

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 55.83%. Comparing base (a272a11) to head (741693b).

Additional details and impacted files

Impacted file tree graph

@@            Coverage Diff             @@
##           master    #1361      +/-   ##
==========================================
+ Coverage   55.78%   55.83%   +0.04%     
==========================================
  Files          89       89              
  Lines        4508     4508              
==========================================
+ Hits         2515     2517       +2     
+ Misses       1802     1801       -1     
+ Partials      191      190       -1     

see 1 file with indirect coverage changes

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

@red-hat-konflux red-hat-konflux bot force-pushed the konflux/mintmaker/master/rpm-lockfile-refresh-vulnerability branch from 26a2e66 to 6ddf4ce Compare March 12, 2026 16:24
@red-hat-konflux red-hat-konflux bot force-pushed the konflux/mintmaker/master/rpm-lockfile-refresh-vulnerability branch from 6ddf4ce to 5459b9d Compare March 24, 2026 12:28
@red-hat-konflux red-hat-konflux bot force-pushed the konflux/mintmaker/master/rpm-lockfile-refresh-vulnerability branch 2 times, most recently from 1b4314b to 9994f91 Compare April 2, 2026 16:18
@red-hat-konflux red-hat-konflux bot force-pushed the konflux/mintmaker/master/rpm-lockfile-refresh-vulnerability branch from 9994f91 to bff4d88 Compare April 14, 2026 00:16
@openshift-ci openshift-ci bot added the needs-rebase Indicates a PR cannot be merged because it has merge conflicts with HEAD. label Apr 14, 2026
@red-hat-konflux red-hat-konflux bot force-pushed the konflux/mintmaker/master/rpm-lockfile-refresh-vulnerability branch from bff4d88 to 15ab6c1 Compare April 14, 2026 04:18
@openshift-ci openshift-ci bot removed the needs-rebase Indicates a PR cannot be merged because it has merge conflicts with HEAD. label Apr 14, 2026
@red-hat-konflux red-hat-konflux bot force-pushed the konflux/mintmaker/master/rpm-lockfile-refresh-vulnerability branch 2 times, most recently from 4303707 to a79477d Compare April 16, 2026 12:16
Signed-off-by: red-hat-konflux <126015336+red-hat-konflux[bot]@users.noreply.github.com>
@red-hat-konflux red-hat-konflux bot force-pushed the konflux/mintmaker/master/rpm-lockfile-refresh-vulnerability branch from a79477d to 741693b Compare April 16, 2026 20:13
@openshift-ci
Copy link
Copy Markdown

openshift-ci bot commented Apr 16, 2026

@red-hat-konflux[bot]: all tests passed!

Full PR test history. Your PR dashboard.

Details

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. I understand the commands that are listed here.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

jira/valid-reference Indicates that this PR references a valid Jira ticket of any type. size/L Denotes a PR that changes 100-499 lines, ignoring generated files.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant