{"id":"CGA-j372-gcfv-2369","modified":"2026-03-11T06:46:08.813490Z","published":"2026-01-15T03:58:28.050160Z","related":["CVE-2024-29902","GHSA-88jx-383q-w4qc","GO-2024-2718"],"affected":[{"package":{"name":"aactl","ecosystem":"Chainguard","purl":"pkg:apk/chainguard/aactl"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.4.12-r10"}]}],"database_specific":{"source":"https://packages.cgr.dev/chainguard/osv/CGA-j372-gcfv-2369.json"}},{"package":{"name":"apko","ecosystem":"Chainguard","purl":"pkg:apk/chainguard/apko"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.14.0-r6"}]}],"database_specific":{"source":"https://packages.cgr.dev/chainguard/osv/CGA-j372-gcfv-2369.json"}},{"package":{"name":"chainctl","ecosystem":"Chainguard","purl":"pkg:apk/chainguard/chainctl"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.2.59-r0"}]}],"database_specific":{"source":"https://packages.cgr.dev/chainguard/osv/CGA-j372-gcfv-2369.json"}},{"package":{"name":"docker-credential-cgr","ecosystem":"Chainguard","purl":"pkg:apk/chainguard/docker-credential-cgr"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.2.59-r0"}]}],"database_specific":{"source":"https://packages.cgr.dev/chainguard/osv/CGA-j372-gcfv-2369.json"}},{"package":{"name":"falco","ecosystem":"Chainguard","purl":"pkg:apk/chainguard/falco"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.37.1-r0"}]}],"database_specific":{"source":"https://packages.cgr.dev/chainguard/osv/CGA-j372-gcfv-2369.json"}},{"package":{"name":"falcoctl","ecosystem":"Chainguard","purl":"pkg:apk/chainguard/falcoctl"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.7.3-r7"}]}],"database_specific":{"source":"https://packages.cgr.dev/chainguard/osv/CGA-j372-gcfv-2369.json"}},{"package":{"name":"falcoctl-fips","ecosystem":"Chainguard","purl":"pkg:apk/chainguard/falcoctl-fips"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.7.3-r8"}]}],"database_specific":{"source":"https://packages.cgr.dev/chainguard/osv/CGA-j372-gcfv-2369.json"}},{"package":{"name":"flux-source-controller","ecosystem":"Chainguard","purl":"pkg:apk/chainguard/flux-source-controller"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.2.5-r1"}]}],"database_specific":{"source":"https://packages.cgr.dev/chainguard/osv/CGA-j372-gcfv-2369.json"}},{"package":{"name":"gitsign","ecosystem":"Chainguard","purl":"pkg:apk/chainguard/gitsign"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.10.1-r2"}]}],"database_specific":{"source":"https://packages.cgr.dev/chainguard/osv/CGA-j372-gcfv-2369.json"}},{"package":{"name":"goreleaser","ecosystem":"Chainguard","purl":"pkg:apk/chainguard/goreleaser"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.26.0-r0"}]}],"database_specific":{"source":"https://packages.cgr.dev/chainguard/osv/CGA-j372-gcfv-2369.json"}},{"package":{"name":"goreleaser-1.18","ecosystem":"Chainguard","purl":"pkg:apk/chainguard/goreleaser-1.18"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.18.2-r12"}]}],"database_specific":{"source":"https://packages.cgr.dev/chainguard/osv/CGA-j372-gcfv-2369.json"}},{"package":{"name":"ko","ecosystem":"Chainguard","purl":"pkg:apk/chainguard/ko"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.15.2-r6"}]}],"database_specific":{"source":"https://packages.cgr.dev/chainguard/osv/CGA-j372-gcfv-2369.json"}},{"package":{"name":"ko-fips","ecosystem":"Chainguard","purl":"pkg:apk/chainguard/ko-fips"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.15.2-r4"}]}],"database_specific":{"source":"https://packages.cgr.dev/chainguard/osv/CGA-j372-gcfv-2369.json"}},{"package":{"name":"kubescape","ecosystem":"Chainguard","purl":"pkg:apk/chainguard/kubescape"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.0.8-r2"}]}],"database_specific":{"source":"https://packages.cgr.dev/chainguard/osv/CGA-j372-gcfv-2369.json"}},{"package":{"name":"melange","ecosystem":"Chainguard","purl":"pkg:apk/chainguard/melange"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.6.11-r1"}]}],"database_specific":{"source":"https://packages.cgr.dev/chainguard/osv/CGA-j372-gcfv-2369.json"}},{"package":{"name":"neuvector-sigstore-interface","ecosystem":"Chainguard","purl":"pkg:apk/chainguard/neuvector-sigstore-interface"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0_git20240520-r1"}]}],"database_specific":{"source":"https://packages.cgr.dev/chainguard/osv/CGA-j372-gcfv-2369.json"}},{"package":{"name":"policy-controller","ecosystem":"Chainguard","purl":"pkg:apk/chainguard/policy-controller"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.9.0-r0"}]}],"database_specific":{"source":"https://packages.cgr.dev/chainguard/osv/CGA-j372-gcfv-2369.json"}},{"package":{"name":"policy-controller-fips","ecosystem":"Chainguard","purl":"pkg:apk/chainguard/policy-controller-fips"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.9.0-r0"}]}],"database_specific":{"source":"https://packages.cgr.dev/chainguard/osv/CGA-j372-gcfv-2369.json"}},{"package":{"name":"policy-controller-tester","ecosystem":"Chainguard","purl":"pkg:apk/chainguard/policy-controller-tester"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.9.0-r0"}]}],"database_specific":{"source":"https://packages.cgr.dev/chainguard/osv/CGA-j372-gcfv-2369.json"}},{"package":{"name":"policy-controller-tester-fips","ecosystem":"Chainguard","purl":"pkg:apk/chainguard/policy-controller-tester-fips"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.9.0-r0"}]}],"database_specific":{"source":"https://packages.cgr.dev/chainguard/osv/CGA-j372-gcfv-2369.json"}},{"package":{"name":"policy-controller-webhook","ecosystem":"Chainguard","purl":"pkg:apk/chainguard/policy-controller-webhook"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.9.0-r0"}]}],"database_specific":{"source":"https://packages.cgr.dev/chainguard/osv/CGA-j372-gcfv-2369.json"}},{"package":{"name":"skaffold","ecosystem":"Chainguard","purl":"pkg:apk/chainguard/skaffold"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.11.1-r1"}]}],"database_specific":{"source":"https://packages.cgr.dev/chainguard/osv/CGA-j372-gcfv-2369.json"}},{"package":{"name":"slsa-verifier","ecosystem":"Chainguard","purl":"pkg:apk/chainguard/slsa-verifier"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.5.1-r4"}]}],"database_specific":{"source":"https://packages.cgr.dev/chainguard/osv/CGA-j372-gcfv-2369.json"}},{"package":{"name":"spire-server","ecosystem":"Chainguard","purl":"pkg:apk/chainguard/spire-server"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.9.4-r1"}]}],"database_specific":{"source":"https://packages.cgr.dev/chainguard/osv/CGA-j372-gcfv-2369.json"}},{"package":{"name":"spire-server-fips","ecosystem":"Chainguard","purl":"pkg:apk/chainguard/spire-server-fips"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.9.4-r2"}]}],"database_specific":{"source":"https://packages.cgr.dev/chainguard/osv/CGA-j372-gcfv-2369.json"}},{"package":{"name":"tekton-chains","ecosystem":"Chainguard","purl":"pkg:apk/chainguard/tekton-chains"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.20.1-r3"}]}],"database_specific":{"source":"https://packages.cgr.dev/chainguard/osv/CGA-j372-gcfv-2369.json"}},{"package":{"name":"tekton-chains-fips","ecosystem":"Chainguard","purl":"pkg:apk/chainguard/tekton-chains-fips"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.20.1-r3"}]}],"database_specific":{"source":"https://packages.cgr.dev/chainguard/osv/CGA-j372-gcfv-2369.json"}},{"package":{"name":"tkn","ecosystem":"Chainguard","purl":"pkg:apk/chainguard/tkn"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.36.0-r3"}]}],"database_specific":{"source":"https://packages.cgr.dev/chainguard/osv/CGA-j372-gcfv-2369.json"}},{"package":{"name":"tkn-fips","ecosystem":"Chainguard","purl":"pkg:apk/chainguard/tkn-fips"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.36.0-r3"}]}],"database_specific":{"source":"https://packages.cgr.dev/chainguard/osv/CGA-j372-gcfv-2369.json"}},{"package":{"name":"vexctl","ecosystem":"Chainguard","purl":"pkg:apk/chainguard/vexctl"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.2.6-r7"}]}],"database_specific":{"source":"https://packages.cgr.dev/chainguard/osv/CGA-j372-gcfv-2369.json"}},{"package":{"name":"wolfictl","ecosystem":"Chainguard","purl":"pkg:apk/chainguard/wolfictl"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.15.18-r1"}]}],"database_specific":{"source":"https://packages.cgr.dev/chainguard/osv/CGA-j372-gcfv-2369.json"}},{"package":{"name":"zarf","ecosystem":"Chainguard","purl":"pkg:apk/chainguard/zarf"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.33.0-r1"}]}],"database_specific":{"source":"https://packages.cgr.dev/chainguard/osv/CGA-j372-gcfv-2369.json"}},{"package":{"name":"zot","ecosystem":"Chainguard","purl":"pkg:apk/chainguard/zot"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.0.3-r3"}]}],"database_specific":{"source":"https://packages.cgr.dev/chainguard/osv/CGA-j372-gcfv-2369.json"}},{"package":{"name":"aactl","ecosystem":"Wolfi","purl":"pkg:apk/wolfi/aactl"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.4.12-r10"}]}],"database_specific":{"source":"https://packages.cgr.dev/chainguard/osv/CGA-j372-gcfv-2369.json"}},{"package":{"name":"apko","ecosystem":"Wolfi","purl":"pkg:apk/wolfi/apko"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.14.0-r6"}]}],"database_specific":{"source":"https://packages.cgr.dev/chainguard/osv/CGA-j372-gcfv-2369.json"}},{"package":{"name":"falco","ecosystem":"Wolfi","purl":"pkg:apk/wolfi/falco"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.37.1-r0"}]}],"database_specific":{"source":"https://packages.cgr.dev/chainguard/osv/CGA-j372-gcfv-2369.json"}},{"package":{"name":"falcoctl","ecosystem":"Wolfi","purl":"pkg:apk/wolfi/falcoctl"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.7.3-r7"}]}],"database_specific":{"source":"https://packages.cgr.dev/chainguard/osv/CGA-j372-gcfv-2369.json"}},{"package":{"name":"flux-source-controller","ecosystem":"Wolfi","purl":"pkg:apk/wolfi/flux-source-controller"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.2.5-r1"}]}],"database_specific":{"source":"https://packages.cgr.dev/chainguard/osv/CGA-j372-gcfv-2369.json"}},{"package":{"name":"gitsign","ecosystem":"Wolfi","purl":"pkg:apk/wolfi/gitsign"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.10.1-r2"}]}],"database_specific":{"source":"https://packages.cgr.dev/chainguard/osv/CGA-j372-gcfv-2369.json"}},{"package":{"name":"goreleaser","ecosystem":"Wolfi","purl":"pkg:apk/wolfi/goreleaser"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.26.0-r0"}]}],"database_specific":{"source":"https://packages.cgr.dev/chainguard/osv/CGA-j372-gcfv-2369.json"}},{"package":{"name":"goreleaser-1.18","ecosystem":"Wolfi","purl":"pkg:apk/wolfi/goreleaser-1.18"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.18.2-r12"}]}],"database_specific":{"source":"https://packages.cgr.dev/chainguard/osv/CGA-j372-gcfv-2369.json"}},{"package":{"name":"ko","ecosystem":"Wolfi","purl":"pkg:apk/wolfi/ko"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.15.2-r6"}]}],"database_specific":{"source":"https://packages.cgr.dev/chainguard/osv/CGA-j372-gcfv-2369.json"}},{"package":{"name":"ko-fips","ecosystem":"Wolfi","purl":"pkg:apk/wolfi/ko-fips"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.15.2-r4"}]}],"database_specific":{"source":"https://packages.cgr.dev/chainguard/osv/CGA-j372-gcfv-2369.json"}},{"package":{"name":"kubescape","ecosystem":"Wolfi","purl":"pkg:apk/wolfi/kubescape"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.0.8-r2"}]}],"database_specific":{"source":"https://packages.cgr.dev/chainguard/osv/CGA-j372-gcfv-2369.json"}},{"package":{"name":"melange","ecosystem":"Wolfi","purl":"pkg:apk/wolfi/melange"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.6.11-r1"}]}],"database_specific":{"source":"https://packages.cgr.dev/chainguard/osv/CGA-j372-gcfv-2369.json"}},{"package":{"name":"neuvector-sigstore-interface","ecosystem":"Wolfi","purl":"pkg:apk/wolfi/neuvector-sigstore-interface"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0_git20240520-r1"}]}],"database_specific":{"source":"https://packages.cgr.dev/chainguard/osv/CGA-j372-gcfv-2369.json"}},{"package":{"name":"policy-controller","ecosystem":"Wolfi","purl":"pkg:apk/wolfi/policy-controller"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.9.0-r0"}]}],"database_specific":{"source":"https://packages.cgr.dev/chainguard/osv/CGA-j372-gcfv-2369.json"}},{"package":{"name":"policy-controller-tester","ecosystem":"Wolfi","purl":"pkg:apk/wolfi/policy-controller-tester"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.9.0-r0"}]}],"database_specific":{"source":"https://packages.cgr.dev/chainguard/osv/CGA-j372-gcfv-2369.json"}},{"package":{"name":"policy-controller-webhook","ecosystem":"Wolfi","purl":"pkg:apk/wolfi/policy-controller-webhook"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.9.0-r0"}]}],"database_specific":{"source":"https://packages.cgr.dev/chainguard/osv/CGA-j372-gcfv-2369.json"}},{"package":{"name":"skaffold","ecosystem":"Wolfi","purl":"pkg:apk/wolfi/skaffold"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.11.1-r1"}]}],"database_specific":{"source":"https://packages.cgr.dev/chainguard/osv/CGA-j372-gcfv-2369.json"}},{"package":{"name":"slsa-verifier","ecosystem":"Wolfi","purl":"pkg:apk/wolfi/slsa-verifier"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.5.1-r4"}]}],"database_specific":{"source":"https://packages.cgr.dev/chainguard/osv/CGA-j372-gcfv-2369.json"}},{"package":{"name":"spire-server","ecosystem":"Wolfi","purl":"pkg:apk/wolfi/spire-server"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.9.4-r1"}]}],"database_specific":{"source":"https://packages.cgr.dev/chainguard/osv/CGA-j372-gcfv-2369.json"}},{"package":{"name":"tekton-chains","ecosystem":"Wolfi","purl":"pkg:apk/wolfi/tekton-chains"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.20.1-r3"}]}],"database_specific":{"source":"https://packages.cgr.dev/chainguard/osv/CGA-j372-gcfv-2369.json"}},{"package":{"name":"tkn","ecosystem":"Wolfi","purl":"pkg:apk/wolfi/tkn"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.36.0-r3"}]}],"database_specific":{"source":"https://packages.cgr.dev/chainguard/osv/CGA-j372-gcfv-2369.json"}},{"package":{"name":"vexctl","ecosystem":"Wolfi","purl":"pkg:apk/wolfi/vexctl"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.2.6-r7"}]}],"database_specific":{"source":"https://packages.cgr.dev/chainguard/osv/CGA-j372-gcfv-2369.json"}},{"package":{"name":"wolfictl","ecosystem":"Wolfi","purl":"pkg:apk/wolfi/wolfictl"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.15.18-r1"}]}],"database_specific":{"source":"https://packages.cgr.dev/chainguard/osv/CGA-j372-gcfv-2369.json"}},{"package":{"name":"zarf","ecosystem":"Wolfi","purl":"pkg:apk/wolfi/zarf"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.33.0-r1"}]}],"database_specific":{"source":"https://packages.cgr.dev/chainguard/osv/CGA-j372-gcfv-2369.json"}},{"package":{"name":"zot","ecosystem":"Wolfi","purl":"pkg:apk/wolfi/zot"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.0.3-r3"}]}],"database_specific":{"source":"https://packages.cgr.dev/chainguard/osv/CGA-j372-gcfv-2369.json"}}],"schema_version":"1.7.5"}