Security Advisories for chainguard.dev/apko in go
High
about 1 month ago
melange: Incomplete package integrity verification allows data section substitution
go
chainguard.dev/melange, chainguard.dev/apko
High
3 months ago
apko doesn't verify downloaded apk packages against APKINDEX checksum (package substitution possible)
go
chainguard.dev/apko
High
3 months ago
apko dirFS has a symlink-following path traversal that allows multiple entry points to escape the build root
go
chainguard.dev/apko
Moderate
3 months ago
apko `DiscoverKeys` has a panic on non-rsa jwks key that causes crash during key discovery
go
chainguard.dev/apko
Moderate
6 months ago
apko affected by unbounded resource consumption in expandapk.Split on attacker-controlled .apk streams
go
chainguard.dev/apko
High
6 months ago
apko has a path traversal in apko dirFS which allows filesystem writes outside base
go
chainguard.dev/apko
High
about 1 year ago
apko is vulnerable to attack through incorrect permissions in /etc/ld.so.cache and other files
go
chainguard.dev/apko
High
about 2 years ago
apko Exposure of HTTP basic auth credentials in log output
go
chainguard.dev/apko