-
Notifications
You must be signed in to change notification settings - Fork 250
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
fmt/11.0.2 package update #24349
fmt/11.0.2 package update #24349
Conversation
octo-sts
bot
commented
Jul 20, 2024
Signed-off-by: wolfi-bot <121097084+wolfi-bot@users.noreply.github.com>
Package fmt-dev: Click to expand/collapsePackage fmt-dev: Package fmt: Click to expand/collapsePackage fmt: bincapz found differences: Click to expand/collapseChanged: /tmp/wolfictl-apk-3256227662/fmt/var/lib/db/sbom/fmt-11.0.2-r0.spdx.json [✅ →
|
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+MEDIUM | net/download | download files | downloadLocation |
+LOW | ref/site/url | contains embedded HTTPS URLs | https://spdx.org/spdxdocs/chainguard/melange/d8617a465698f84484aeae5eedac |
Changed: /tmp/wolfictl-apk-3256227662/fmt/usr/lib/libfmt.so.11.0.2 [⚠️ MEDIUM → ✅ ]
2 removed behaviors
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
-MEDIUM | net/download | download files | downloadLocation |
-LOW | ref/site/url | contains embedded HTTPS URLs | https://spdx.org/spdxdocs/chainguard/melange/206ca18adf9341e9f344b7831027 |
Changed: /tmp/wolfictl-apk-3256227662/fmt-dev/var/lib/db/sbom/fmt-dev-11.0.2-r0.spdx.json [✅ → ⚠️ MEDIUM]
2 new behaviors
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+MEDIUM | net/download | download files | downloadLocation |
+LOW | ref/site/url | contains embedded HTTPS URLs | https://spdx.org/spdxdocs/chainguard/melange/7d53d6ed8418b2a7141ebaaae0c4 |
Changed: /tmp/wolfictl-apk-3256227662/fmt-dev/usr/include/fmt/base.h [✅ → ✅ LOW]
1 new behaviors
Open AI suggestions to solve the build error:
|
Signed-off-by: James Rawlings <jrawlings@chainguard.dev>
Open AI suggestions to solve the build error:
|
Open AI suggestions to solve the build error:
|
Package fmt: Click to expand/collapsePackage fmt: Package spdlog: Click to expand/collapsePackage spdlog: Package libmamba-dev: Click to expand/collapsePackage libmamba-dev: Package mamba-package: Click to expand/collapsePackage mamba-package: Package fmt-dev: Click to expand/collapsePackage fmt-dev: Package spdlog-dev: Click to expand/collapsePackage spdlog-dev: Package libmamba: Click to expand/collapsePackage libmamba: Package py3-libmambapy: Click to expand/collapsePackage py3-libmambapy: Package micromamba: Click to expand/collapsePackage micromamba: bincapz found differences: Click to expand/collapseChanged: /tmp/wolfictl-apk-3700312557/spdlog-dev/var/lib/db/sbom/spdlog-dev-1.14.1-r1.spdx.jsonChanged: /tmp/wolfictl-apk-3700312557/fmt-dev/usr/include/fmt/base.h [✅ → ✅ LOW]1 new behaviorsChanged: /tmp/wolfictl-apk-3700312557/fmt-dev/var/lib/db/sbom/fmt-dev-11.0.2-r0.spdx.jsonMoved: spdlog-dev/var/lib/db/sbom/spdlog-dev-1.14.1-r0.spdx.json -> /tmp/wolfictl-apk-3700312557/spdlog/var/lib/db/sbom/spdlog-1.14.1-r1.spdx.json (similarity: 0.91)Changed: /tmp/wolfictl-apk-3700312557/fmt/var/lib/db/sbom/fmt-11.0.2-r0.spdx.json [✅ →
|
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+MEDIUM | net/download | download files | downloadLocation |
+LOW | ref/site/url | contains embedded HTTPS URLs | https://spdx.org/spdxdocs/chainguard/melange/d8617a465698f84484aeae5eedac |
Changed: /tmp/wolfictl-apk-3700312557/fmt/usr/lib/libfmt.so.11.0.2 [⚠️ MEDIUM → ✅ ]
2 removed behaviors
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
-MEDIUM | net/download | download files | downloadLocation |
-LOW | ref/site/url | contains embedded HTTPS URLs | https://spdx.org/spdxdocs/chainguard/melange/624b623bc0307f2ad686298a003e |
Open AI suggestions to solve the build error:
|
Signed-off-by: Dimitri John Ledkov <dimitri.ledkov@chainguard.dev>
beb77a5
to
5e3c054
Compare
Package py3-libmambapy: Click to expand/collapsePackage py3-libmambapy: Package micromamba: Click to expand/collapsePackage micromamba: Package mamba-package: Click to expand/collapsePackage mamba-package: Package fmt: Click to expand/collapsePackage fmt: Package fmt-dev: Click to expand/collapsePackage fmt-dev: Package spdlog: Click to expand/collapsePackage spdlog: Package spdlog-dev: Click to expand/collapsePackage spdlog-dev: Package libmamba: Click to expand/collapsePackage libmamba: Package libmamba-dev: Click to expand/collapsePackage libmamba-dev: bincapz found differences: Click to expand/collapseChanged: /tmp/wolfictl-apk-2084580459/fmt-dev/usr/include/fmt/base.h [
|
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
-MEDIUM | net/download | download files | downloadLocation |
Changed: /tmp/wolfictl-apk-2084580459/fmt/var/lib/db/sbom/fmt-11.0.2-r0.spdx.json
Changed: /tmp/wolfictl-apk-2084580459/fmt/usr/lib/libfmt.so.11.0.2 [⚠️ MEDIUM → ✅ ]
2 removed behaviors
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
-MEDIUM | net/download | download files | downloadLocation |
-LOW | ref/site/url | contains embedded HTTPS URLs | https://spdx.org/spdxdocs/chainguard/melange/206ca18adf9341e9f344b7831027 |
Changed: /tmp/wolfictl-apk-2084580459/fmt-dev/var/lib/db/sbom/fmt-dev-11.0.2-r0.spdx.json
Moved: spdlog/var/lib/db/sbom/spdlog-1.14.1-r0.spdx.json -> /tmp/wolfictl-apk-2084580459/spdlog/var/lib/db/sbom/spdlog-1.14.1-r1.spdx.json (similarity: 0.99)
Changed: /tmp/wolfictl-apk-2084580459/spdlog-dev/var/lib/db/sbom/spdlog-dev-1.14.1-r1.spdx.json
Open AI suggestions to solve the build error:
|
Signed-off-by: jamie-albert <jamie.albert@chainguard.dev>
Package mamba-package: Click to expand/collapsePackage mamba-package: Package fmt: Click to expand/collapsePackage fmt: Package fmt-dev: Click to expand/collapsePackage fmt-dev: Package py3-libmambapy: Click to expand/collapsePackage py3-libmambapy: Package libmamba-dev: Click to expand/collapsePackage libmamba-dev: Package micromamba: Click to expand/collapsePackage micromamba: Package spdlog: Click to expand/collapsePackage spdlog: Package spdlog-dev: Click to expand/collapsePackage spdlog-dev: Package libmamba: Click to expand/collapsePackage libmamba: bincapz found differences: Click to expand/collapseChanged: /tmp/wolfictl-apk-3357208289/fmt-dev/var/lib/db/sbom/fmt-dev-11.0.2-r1.spdx.jsonChanged: /tmp/wolfictl-apk-3357208289/libmamba-dev/var/lib/db/sbom/libmamba-dev-2024.03.25-r4.spdx.jsonChanged: /tmp/wolfictl-apk-3357208289/micromamba/var/lib/db/sbom/micromamba-2024.03.25-r4.spdx.jsonChanged: /tmp/wolfictl-apk-3357208289/libmamba/var/lib/db/sbom/libmamba-2024.03.25-r4.spdx.jsonChanged: /tmp/wolfictl-apk-3357208289/spdlog-dev/var/lib/db/sbom/spdlog-dev-1.14.1-r2.spdx.jsonChanged: /tmp/wolfictl-apk-3357208289/fmt-dev/usr/include/fmt/base.h [✅ → ✅ LOW]1 new behaviorsChanged: /tmp/wolfictl-apk-3357208289/mamba-package/var/lib/db/sbom/mamba-package-2024.03.25-r4.spdx.jsonChanged: /tmp/wolfictl-apk-3357208289/py3-libmambapy/var/lib/db/sbom/py3-libmambapy-2024.03.25-r4.spdx.jsonMoved: spdlog-dev/var/lib/db/sbom/spdlog-dev-1.14.1-r0.spdx.json -> /tmp/wolfictl-apk-3357208289/spdlog/var/lib/db/sbom/spdlog-1.14.1-r2.spdx.json (similarity: 0.91)Changed: /tmp/wolfictl-apk-3357208289/fmt/var/lib/db/sbom/fmt-11.0.2-r1.spdx.jsonChanged: /tmp/wolfictl-apk-3357208289/fmt/usr/lib/libfmt.so.11.0.2 [
|
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
-MEDIUM | net/download | download files | downloadLocation |
-LOW | ref/site/url | contains embedded HTTPS URLs | https://spdx.org/spdxdocs/chainguard/melange/a1e34d2c81f3046273c33652e030 |
Open AI suggestions to solve the build error:
|
Package py3-libmambapy: Click to expand/collapsePackage py3-libmambapy: Package micromamba: Click to expand/collapsePackage micromamba: Package fmt: Click to expand/collapsePackage fmt: Package libmamba: Click to expand/collapsePackage libmamba: Package spdlog-dev: Click to expand/collapsePackage spdlog-dev: Package libmamba-dev: Click to expand/collapsePackage libmamba-dev: Package mamba-package: Click to expand/collapsePackage mamba-package: Package fmt-dev: Click to expand/collapsePackage fmt-dev: Package spdlog: Click to expand/collapsePackage spdlog: bincapz found differences: Click to expand/collapseChanged: /tmp/wolfictl-apk-54742022/fmt/var/lib/db/sbom/fmt-11.0.2-r0.spdx.jsonChanged: /tmp/wolfictl-apk-54742022/fmt-dev/var/lib/db/sbom/fmt-dev-11.0.2-r0.spdx.json [✅ →
|
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
+MEDIUM | net/download | download files | downloadLocation |
+LOW | ref/site/url | contains embedded HTTPS URLs | https://spdx.org/spdxdocs/chainguard/melange/7d53d6ed8418b2a7141ebaaae0c4 |
Changed: /tmp/wolfictl-apk-54742022/fmt-dev/usr/include/fmt/base.h [✅ → ✅ LOW]
1 new behaviors
Changed: /tmp/wolfictl-apk-54742022/fmt/usr/lib/libfmt.so.11.0.2 [⚠️ MEDIUM → ✅ ]
2 removed behaviors
RISK | KEY | DESCRIPTION | EVIDENCE |
---|---|---|---|
-MEDIUM | net/download | download files | downloadLocation |
-LOW | ref/site/url | contains embedded HTTPS URLs | https://spdx.org/spdxdocs/chainguard/melange/a1e34d2c81f3046273c33652e030 |
Changed: /tmp/wolfictl-apk-54742022/spdlog-dev/var/lib/db/sbom/spdlog-dev-1.14.1-r1.spdx.json
Changed: /tmp/wolfictl-apk-54742022/spdlog/var/lib/db/sbom/spdlog-1.14.1-r1.spdx.json
Open AI suggestions to solve the build error:
|
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Upstream patch resolves build error
The ABI compatibility check is failing and will need addressing in the dependent packages. |
that's what the two bumps of defendant packages are for, there are no other reverse dependencies. |