This repository was archived by the owner on Jan 7, 2026. It is now read-only.
-
Notifications
You must be signed in to change notification settings - Fork 89
Expand file tree
/
Copy pathbento.advisories.yaml
More file actions
141 lines (134 loc) · 3.86 KB
/
Copy pathbento.advisories.yaml
File metadata and controls
141 lines (134 loc) · 3.86 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
schema-version: 2.0.2
package:
name: bento
advisories:
- id: CGA-4j8c-g5fw-r58q
aliases:
- CVE-2025-10543
- GHSA-32fw-gq77-f2f2
events:
- timestamp: 2025-12-03T11:07:45Z
type: detection
data:
type: scan/v1
data:
subpackageName: bento
componentID: c0f868ac575c7e6e
componentName: github.com/eclipse/paho.mqtt.golang
componentVersion: v1.4.3
componentType: go-module
componentLocation: /usr/bin/bento
scanner: grype
- timestamp: 2025-12-04T17:14:55Z
type: fixed
data:
fixed-version: 1.13.1-r0
- id: CGA-84q3-wjxc-6j67
aliases:
- CVE-2025-47907
- GHSA-j5pm-7495-qmr3
events:
- timestamp: 2025-08-10T05:22:39Z
type: detection
data:
type: scan/v1
data:
subpackageName: bento
componentID: e59eafc62b1e194b
componentName: stdlib
componentVersion: go1.24.5
componentType: go-module
componentLocation: /usr/bin/bento
scanner: grype
- timestamp: 2025-08-10T07:38:33Z
type: true-positive-determination
data:
note: 'Govulncheck found vulnerable symbols in Go binaries at the following locations: in bento-1.9.1-r0.apk, at usr/bin/bento, usr/bin/bento.'
- timestamp: 2025-08-10T23:42:17Z
type: fixed
data:
fixed-version: 1.9.1-r1
- id: CGA-945v-8h64-r3jm
aliases:
- CVE-2025-47914
- GHSA-f6x5-jh6r-wrfv
events:
- timestamp: 2025-11-21T07:43:25Z
type: detection
data:
type: scan/v1
data:
subpackageName: bento
componentID: 39ba55d44aeecdf4
componentName: golang.org/x/crypto
componentVersion: v0.40.0
componentType: go-module
componentLocation: /usr/bin/bento
scanner: grype
- timestamp: 2025-11-21T10:50:22Z
type: fixed
data:
fixed-version: 1.12.1-r3
- id: CGA-mwxw-ph3f-mg7r
aliases:
- CVE-2025-58181
- GHSA-j5w8-q4qc-rx2x
events:
- timestamp: 2025-11-21T07:43:26Z
type: detection
data:
type: scan/v1
data:
subpackageName: bento
componentID: 39ba55d44aeecdf4
componentName: golang.org/x/crypto
componentVersion: v0.40.0
componentType: go-module
componentLocation: /usr/bin/bento
scanner: grype
- timestamp: 2025-11-21T10:50:23Z
type: fixed
data:
fixed-version: 1.12.1-r3
- id: CGA-p9cj-r57v-m82x
aliases:
- CVE-2025-54410
- GHSA-4vq8-7jfc-9cvp
events:
- timestamp: 2025-08-16T07:06:07Z
type: detection
data:
type: scan/v1
data:
subpackageName: bento
componentID: 82172ecb6a0b1f62
componentName: github.com/docker/docker
componentVersion: v27.5.1+incompatible
componentType: go-module
componentLocation: /usr/bin/bento
scanner: grype
- timestamp: 2025-08-16T08:42:09Z
type: fixed
data:
fixed-version: 1.10.0-r1
- id: CGA-vm6m-q74c-jff6
aliases:
- CVE-2025-63811
- GHSA-9mj6-hxhv-w67j
events:
- timestamp: 2025-11-18T07:05:19Z
type: detection
data:
type: scan/v1
data:
subpackageName: bento
componentID: 59dfe6f333ef5451
componentName: github.com/dvsekhvalnov/jose2go
componentVersion: v1.6.0
componentType: go-module
componentLocation: /usr/bin/bento
scanner: grype
- timestamp: 2025-11-18T08:32:13Z
type: fixed
data:
fixed-version: 1.12.1-r2